Advanced Plus Security RoxasDev's PC Security Config

Original forum configuration · expand details
Thread details
Last updated
Oct 7, 2026
Main use of this computer
For home and private use
Operating system
Windows 11
OS version and support details
26H2
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Hardware security key
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
    • Automatic sign-in / no sign-in required
Security updates
Check for updates and Notify
Update channels
Allow stable updates only
User Account Control (UAC)
Notify me only when programs try to make changes to my computer
Smart App Control
On
Network firewall
Enabled
Router and network details
Linksys WRT1900ACS running OpenWrt 25.12.5, with advanced firewall and network filtering rules.
Real-time protection
Microsoft Defender
Device firewall
Microsoft Defender Firewall
Periodic malware scanners
Malwarebytes, ESET Online Scanner, AdwCleaner, ZHPCleaner
Malware sample testing
I participate in malware testing; details below
Environment for malware testing
RxCloud CyberLab — isolated virtual machines dedicated to malware analysis and security research. Test environments are segmented from my personal network and everyday devices, with controlled network access, automated VM restoration, and dedicated monitoring/telemetry.
Browsers and extensions
Brave (Shields enabled), uBlock Origin
Secure DNS
OpenDNS
Desktop VPN
VPN managed by my router via WireGuard
Password and passkey manager
My brain
Two-factor authentication
Microsoft Authentificator
File and photo backups
Veeam
Subscriptions
    • Apple iCloud+ 200GB
    • Other subscription
System recovery
Veeam
Usage and exposure
    • Gaming
    • Coding and development
Computer specs
Custom-built Desktop PC — Intel Core i9-9900K, NVIDIA GeForce RTX 5060 Ti 16 GB, 32 GB RAM, 512 GB NVMe SSD + 1 TB SSD + 2×2 TB HDD
Feedback preference

Detailed suggestions and alternatives welcome

RoxasDev

Level 5
Verified
Developer
Well-known
Forum Veteran
RoxasDev's PC Security Config · Setup v1
Updated Oct 7, 2026

My current setup
  • Operating system: Windows 11
  • OS version and support details: 26H2
  • Real-time protection: Microsoft Defender
  • File and photo backups: Veeam
  • Device firewall: Microsoft Defender Firewall
  • Browsers and extensions: Brave (Shields enabled), uBlock Origin
  • Main use of this computer: For home and private use
  • On-device encryption: Windows BitLocker / Device Encryption
  • Device sign-in security: Hardware security key, Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID), Automatic sign-in / no sign-in required
  • Security updates: Check for updates and Notify
  • Update channels: Allow stable updates only
  • User Account Control (UAC): Notify me only when programs try to make changes to my computer
  • Smart App Control: On
  • Network firewall: Enabled
  • Router and network details: Linksys WRT1900ACS running OpenWrt 25.12.5, with advanced firewall and network filtering rules.
  • Periodic malware scanners: Malwarebytes, ESET Online Scanner, AdwCleaner, ZHPCleaner
  • Malware sample testing: I participate in malware testing; details below
  • Environment for malware testing: RxCloud CyberLab — isolated virtual machines dedicated to malware analysis and security research. Test environments are segmented from my personal network and everyday devices, with controlled network access, automated VM restoration, and dedicated monitoring/telemetry.
  • Secure DNS: OpenDNS
  • Desktop VPN: VPN managed by my router via WireGuard
  • Password and passkey manager: My brain
  • Two-factor authentication: Microsoft Authentificator
  • Subscriptions: Apple iCloud+ 200GB, Other subscription
  • System recovery: Veeam
  • Usage and exposure: Gaming, Coding and development
  • Computer specs: Custom-built Desktop PC — Intel Core i9-9900K, NVIDIA GeForce RTX 5060 Ti 16 GB, 32 GB RAM, 512 GB NVMe SSD + 1 TB SSD + 2×2 TB HDD
  • Feedback preference: Detailed suggestions and alternatives welcome
Feedback on this setup is welcome.
 
My only suggestion: set UAC to Always notify :)

Thanks for the suggestion! :)

I actually used Always notify for a while, but with the amount of development and administrative work I do on this machine, I found it a little too intrusive for my daily workflow. 😭

So I eventually went back to the default UAC level as a compromise between security and usability. But I definitely agree that Always notify is the stronger option from a security perspective. :D
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top