@Andy Ful, If I use Smart App Control, would you recommend any of your tools?
It is hard to recommend a solution to security-oriented guys.

The first problem is whether you can live with your current setup (SAC enabled).
The default Windows 11 built-in setup + SAC + Core Isolation + slightly hardened Edge and Firewall is enough for most people.
There are many possible ways to make this setup stronger, but then you are trying to fight the malware that will probably never attack your computer.
Here is a possible route, if you would like to test step by step the limits of your abilities:
- FirewallHardening (Recommended H_C).
- FirewallHardening (Recommended H_C) + ConfigureDefender HIGH.
- FirewallHardening (Recommended H_C) + ConfigureDefender HIGH + WHHLight (default SWH settings).
- FirewallHardening (Recommended H_C) + ConfigureDefender MAX + WHHLight (default SWH settings).
- etc. (additional tweaking, DocumentsAntiExploit).
- Hard_Configurator
Hard_Configurator includes FirewallHardening, ConfigureDefender, and DocumentsAntiExploit. The Recommended Settings in Hard_Configurator + ConfigureDefender + FirewallHardening + DocumentsAntiExploit are probably the upper limit (still usable) for MT members.
Hard_Configurator can apply more restrictive setting profiles, but such restrictions are intended for special cases.