Windows' Security Tweaks

Will you use these Windows Security Tweaks?


  • Total voters
    53

Av Gurus

Level 29
Trusted
AV-Tester
Joined
Sep 22, 2014
Messages
1,802
OS
Windows 10
#24
hi guys,

So i will put here various tweaks (registry, group policy, etc...) i found around the net to secure Windows more tightly. By doing them , you will reduce the attacks vector and may even remove the need of security solutions.

As a basis there is these articles to secure the network and the system

For Win7: Harden Windows 7 SP1 64bit
For Win10 : Harden Windows 10 - A Security Guide. How to secure Windows 10
Is this your web page or someone else?
If it is yours, are you updating the tweaks?
 
Likes: Sunshine-boy

Av Gurus

Level 29
Trusted
AV-Tester
Joined
Sep 22, 2014
Messages
1,802
OS
Windows 10
#26
Do you have some similar web pages with tweaks in your bookmarks to share with us?
:rolleyes:
 

Av Gurus

Level 29
Trusted
AV-Tester
Joined
Sep 22, 2014
Messages
1,802
OS
Windows 10
#30
System Tweaks

Blocking Unsigned Elevation :

90% of malware are unsigned and will request an elevation from UAC, this trick will block the request.
Create a registry file with this lines :
Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ValidateAdminCodeSignatures"=dword:00000001
If successfully implemented, the next unsigned process/program; won't be allow to execute, and you will have a error box.
To re-enabled unsigned elevation , use the same line but with "dword:00000000"
Is it possible to make some kinda whitelist or something similar with this reg tweak?
I have some portable app who are unsigned and can't run with this tweak (accept change that tweak everytime).
 
Joined
Dec 23, 2014
Messages
1,584
OS
Windows 10
Antivirus
Microsoft
#31
Is it possible to make some kinda whitelist or something similar with this reg tweak?
I have some portable app who are unsigned and can't run with this tweak (accept change that tweak everytime).
No whitelisting possibility. You can run unsigned application using several ways:
  • via scheduled task trick (works only on admin account and run the program elevated);
  • using the bat files to deactivate/activate this feature via the Registry;
  • writing a simple loader script in powerhell or Windows Script Host.
  • running first, the signed file manager as administrator (Total Commander), and using it to run portable applications (they will be run elevated without UAC prompt).
Nither of the above is especially convenient.
 
Last edited:
Joined
Dec 23, 2014
Messages
1,584
OS
Windows 10
Antivirus
Microsoft
#34
They are easily accessible, for example :
Download Group Policy Settings Reference for Windows and Windows Server from Official Microsoft Download Center
https://msdnshared.blob.core.windows.net/media/2017/08/Windows-10-RS2-Security-Baseline-FINAL.zip
But, not many policies are usable for home computers. The most usable are (will be) included in Hard_Configurator.

Edit 1
Edited the link. Open the zip file and look into Documentation folder. Before applying any policy, gogle some info about it.

Edit 2
Manual reg tweaks are recommended only for experienced users, you can easily break your system. Personally, I use Shadow Defender, when testing reg tweaks.
 
Last edited:

Av Gurus

Level 29
Trusted
AV-Tester
Joined
Sep 22, 2014
Messages
1,802
OS
Windows 10
#39
No whitelisting possibility. You can run unsigned application using several ways:
  • using the bat files to deactivate/activate this feature via the Registry;
Can you make that .bat file for me, please?

EDIT:

Can I make a quick reg files for change, like this?
Enable.reg:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ValidateAdminCodeSignatures"=dword:00000001

Disable.reg:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ValidateAdminCodeSignatures"=dword:00000000
 
Last edited:
Likes: Andy Ful
Joined
Dec 23, 2014
Messages
1,584
OS
Windows 10
Antivirus
Microsoft
#40
Can you make that .bat file for me, please?

EDIT:

Can I make a quick reg files for change, like this?
Enable.reg:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ValidateAdminCodeSignatures"=dword:00000001

Disable.reg:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
"ValidateAdminCodeSignatures"=dword:00000000
Yes, they are correct.:)
 
Likes: Av Gurus

Similar Threads

Similar Threads