I made some changes to my configuration, I'll update this post later.
Realtime Protection:
- Replace Comodo Internet Security with Sophos Home. (I like it's web filtering)
2nd opinion scanner:
- Added Sophos Clean (Hitman Pro).
Windows Defender Application Control:
- Use Microsoft Default profile with Recommend Block Rules.
- Using Event Viewer to manually whitelist programs and DLLs blocked by Windows Defender Application Control.
Windows Firewall:
- Custom rules.
User Access Control:
- Only elevate executable files that are signed and validated.
- Automatically deny elevation requests from Standard User Account.
Powershell:
- Only allow Powershell to run signed scripts.
Windows Update:
- Delay quality updates for 7 days.
- Delay feature updates for 1 year.