Advanced Plus Security Victor M Win11 DMZ PWN box configuration

Last updated
Feb 9, 2026
Main use of this computer
For home and private use
Operating system
Windows 11
OS version and support details
n/a
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
    • Account password
Security updates
Allow security updates
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
Evaluation mode
Network firewall
Enabled
Router and network details
WiFi not used because I live in close proximity to others in an apartment complex
Real-time protection
Windows Defender
Hard_Configurator
CyberLock default deny
Group Policy
DSA STIG
Malwarebytes Anti-Exploit (MBAE)
Windows Defender Exploit Protection (lots of apps defined)
Firewall policy outbound = block
Device firewall
Microsoft Defender Firewall with Advanced Security
Custom security settings
Disabled unused Windows Features (minimize attack surface)
Disabled some services
Disabled DCOM
Hardened WMI
Disabled Scheduler service
H_C Blocked LoLbins
Blocked some LoLDrivers
Standard Account as daily driver
Standard Account has no UAC, no runas, cannot elevate to admin
LoLBins cannot call outbound (Andy Full's firewall hardening)
MS Telemetry blocked by ip's.
DSA STIG
Sysmon
SIEM monitoring
Periodic malware scanners
Power Eraser
Malware sample testing
I do not participate in malware testing
Environment for malware testing
n/a
Browsers and extensions
Privacy Badger
Osprey
SafeToOpen
KeePass
Secure DNS
Quad9
Desktop VPN
ProtonVPN
Password and passkey manager
Keepass
Maintenance tools
n/a
File and photo backups
Macrium Reflect
Subscriptions
    • Google One Basic 100GB
    • None
System recovery
Macrium Reflect
Usage and exposure
    • Visiting familiar websites
Computer specs
DELL Latitude 2020
Notable changes
2026-02-09 Changed to CyberLock + H_C
Feedback preference

Detailed suggestions and alternatives welcome

Here is my windows pwn box which sits in the DMZ. Designed for browsing and Office use. Lots of hardening, but expect it to not last 1 week.
Here is my windows pwn box which sits in the DMZ. Designed for browsing and Office use. Lots of hardening, but expect it to not last 1 week.

Hey Victor M,

Sounds like an interesting setup! A "pwn box" in the DMZ for browsing and Office tasks with heavy hardening—I'm curious about the specifics. What kind of hardening measures have you implemented? Things like AppLocker, Windows Defender tweaks, network isolation, or third-party tools?

If it's expected to get compromised in under a week, that could be a great learning opportunity for the community. Feel free to share more details, screenshots, or logs if you're comfortable. We can brainstorm ways to make it last longer or discuss common attack vectors.

Stay safe out there!

Posted on 2025-09-28 at 14:30
 
@Bot Everything is given in Real time security and Custom security. I mainly use WDAC default deny whitelist, plus LoLBin blacklist.
@Victor_M

Thanks for the details! WDAC in default deny mode with whitelisting is a solid choice for application control—it's one of the more robust ways to lock down executables on Windows. Pairing it with a LoLBin blacklist (I assume you're blocking common Living off the Land Binaries like rundll32, certutil, etc.) adds another layer against script-based attacks and lateral movement.

Have you run into any compatibility issues with Office apps or browsers under this setup? For example, does it play nice with macros or browser extensions? Also, what's your approach to updating the whitelist—manual auditing or some automation?

If you're open to it, sharing your WDAC policy XML or the LoLBin list could spark some great discussions here. Always good to see real-world hardening in action, especially in a DMZ-exposed box.

Looking forward to hearing how it holds up!

Posted on 2025-09-28 at 14:55
 
@Bot LoLBin blacklist does have some unwanted side effects, like for some of the applets in old Control Panel. But nothing major. If there is a need for one of those, I unplug Ethernet, login to admin account and disable each individual blacklist temporarily, But how often does one need old Control Panel ?

Some people think that every single Windows feature must be working or else it is not 'good' security. But consider how much old legacy stuff that Windows 11 includes by default, do you really really need all features of Windows XP to work in Win 11?
 
Last edited:
(y)

Now that I'm recovering, I spend part of my time on the PC disabling, switching from automatic to manual, and putting services and processes into efficiency mode.

It's a shame that there are no more Black Viper's Lists to follow.
They were really useful, and you could resume your work even in the following days.

P.S. It seems to me that you didn't include the browser you used.:)
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top