New Update Testing ConfigureDefenderPM (Policy Manager version)

Can I replace Defender hardening consol with ConfigureDefender and FirewallHardening,with an improvement?,a Ai calls the configure Defender(The gold standard) I have appguard usually on locked down?
What is the Defender hardening console, DefenderUI/DUI? The improvement will be firewall rules with FirewallHardening. You should try the Hard_Configurator suite: ConfigureDefender, FirewallHardening, and Hard_Configurator, all with recommended settings; you will not find as easy/set-and-forget default-deny/smart protection! Do remove AppGuard if you decide to try the Hard_Configurator suite.
 
Can I replace Defender hardening consol with ConfigureDefender and FirewallHardening,with an improvement?,a Ai calls the configure Defender(The gold standard) I have appguard usually on locked down?
You won't see any improvement by switching since you already have two powerful programs in DHC and Appguard. Just make sure your browsers are secured with web filtering of some kind.
 
Can I replace Defender hardening consol with ConfigureDefender and FirewallHardening,with an improvement?

DHC shares many features with ConfigureDefender.
Deep Firewall Control is a strong feature, but essentially different from FirewallHardening. Both protect against different attack vectors.
AppGuard Solo can restrict/contain some important LOLBins, but most of them can still make outbound connections.
You could add FirewallHardening to AppGuard and DHC setup, but I am afraid that such a setup would be unnecessarily complex for home usage.
 
Forgot to say thanks for creating this since, as you know, it solves MD's exclusion issue that I always hated.
BTW, I think this is the first time I have seen this ASR rule in action. It blocked a portable curl that I have, which comes with http3 support that the built-in curl lacks.
When I tried to use it, it was blocked as it should be.
1785963326566.png

But when I tried to add it to the ASR exclusion, it wasn't letting me,
1785963495732.png

It worked after disabling MD. Then I could add the exclusion. I haven't had a ASR rule blocking something in a while so didn't remember that disabling the protection is needed.
 
But when I tried to add it to the ASR exclusion, it wasn't letting me,
View attachment 299247
It worked after disabling MD. Then I could add the exclusion.

The ASR exclusions can be added in two ways:
  1. Temporarily setting the concrete ASR rule to Audit + adding an ASR exclusion.
  2. Temporarily disabling real-time protection + adding an ASR exclusion.
 
I had it in action twice.
One time when trying to install a newer vesion of Realtek audio driver, downloaded from Hp website, than that installed by WU.
The second time during uinstalling of AVG.

I have it disabled all the time.
I had a block too while installing MuMu Player yesterday. The installation failed near the end because it blocked something which was needed to complete the installation. I have now also turned it off.
Since it blocking something while installing a driver, like in your case could cause a bigger issue.
 
I had a block too while installing MuMu Player yesterday. The installation failed near the end because it blocked something which was needed to complete the installation. I have now also turned it off.
Since it blocking something while installing a driver, like in your case could cause a bigger issue.
Avast hardened mode paly more nicely with executable files without mark of the web compared to ASR rule of "Block executable files from running unless they meet a prevalence, age, or trusted list criterion".
 
Avast hardened mode paly more nicely with executable files without mark of the web compared to ASR rule of "Block executable files from running unless they meet a prevalence, age, or trusted list criterion".
Yeah, Avast hardened mode is really good. Andy also likes is very much. But I don't use the Block executable files from......ASR rules. I tend to not enable things that has the potential to cause trouble/annoyances. I have the ransomware one, the office and email related ones. Nothing else, I think. I'm not on my PC at the moment.
 
I have to use it to make up for missing reputation check for executables without mark of the web, which may be deliberately applied by certain malware to bypass SmartScreen check.
I see.
I use Andy's Run by SmartScren tool which adds forcing MoTW button on right click.
Sometimes some big downloads are very slow in the browser and I use a download manager to download those things. That's where I mostly use Run By SmartScren just to be sure.
 
I use Andy's Run by SmartScren tool which adds forcing MoTW button on right click
Yes, it is one of the smartest tools I have ever used.
MS should cooperate with developers such as Andy to improve their apps.

I use the ASR rule to monitor executable running by apps already installed, not for manually running installers for the first time.