Advanced Plus Security WhiteMouse's PC Security Config

Original forum configuration · expand details
Last updated
Jan 1, 2023
Main use of this computer
For home and private use
Operating system
macOS 15 Sequoia
On-device encryption
Windows BitLocker / Device Encryption
Device sign-in security
    • Windows Hello PIN or biometric sign-in (face / fingerprint / Touch ID)
Security updates
Allow security updates and latest features
User Account Control (UAC)
Always notify
Smart App Control
Off
Network firewall
Enabled
Real-time protection
Microsoft Defender
Device firewall
Microsoft Defender Firewall
Custom security settings
  • Security Baseline for Windows 11 22H2, Microsoft Edge and Microsoft Office.
  • Custom WDAC policy: Default Windows + Microsoft recommended block rules + Whitelist all files in Program Files by digital signature or hash + HVCI strict mode.
  • Microsoft Edge: Super Duper Secure mode on for all sites.
Periodic malware scanners
None
Malware sample testing
I do not participate in malware testing
Browsers and extensions
Microsoft Edge: Adblock Plus, Bitwarden
Desktop VPN
Mullvad VPN
Password and passkey manager
Bitwarden
Maintenance tools
Storage Sense
File and photo backups
Onedrive
System recovery
Macrium Reflect
Usage and exposure
    • Browsing the Internet without an ad-blocker
    • Visiting unknown or untrusted websites
    • Working from home
    • Opening email attachments
    • Online shopping and card payments
    • Logging into my bank account
    • Downloading software and files from reputable sites
    • Gaming
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Streaming from untrusted sites
Notable changes
2023/1/1: Replace IVPN with Mullvad VPN
2022/12/31: Added Bitwarden extension
2022/12/21: Added Adbock Plus extension
Feedback preference

Showcase only - no advice requested

I got my signed WDAC policies up and running without issue. Feel free to ask anything.
is there a way to install specific program (ie. k-lite codecs it's dropping some files to sys32 directory) without deploying Allow* policy temporarily (disabling WDAC). Modifying supp policy not works because it's somehow blocks random temp/? system32/? directory access and lots of I don't even aware🤔😉
 
Last edited:
is there a way to install specific program (ie. k-lite codecs it's dropping some files to sys32 directory) without deploying Allow* policy temporarily (disabling WDAC). Modifying supp policy not works because it's somehow blocks random temp/? system32/? directory access and lots of I don't even aware🤔😉
This is one thing that I still haven't had an answer for it yet. Many applications updater love to drop an Unsigned file to temp folder, there's not much thing I can do about it. I think the most secure way to install those programs is to deploy base policy with ISG (rule 14) - and hope that it doesn't block any files during install, install the program then revert back to the old base policy.
 
This is one thing that I still haven't had an answer for it yet. Many applications updater love to drop an Unsigned file to temp folder, there's not much thing I can do about it. I think the most secure way to install those programs is to deploy base policy with ISG (rule 14) - and hope that it doesn't block any files during install, install the program then revert back to the old base policy.
in the future I'm planning to add temp/ ProgramFiles*/ ProgramData and system32/ as FilePath rules to unsigned supp policy for test purposes(I'm aware it's posseses risk but CS-CFW will handle the rest 👩🏼‍🦲🤷🏽‍♀️)
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top