Advanced Security Xeno1234's PC Security Config

Original forum configuration · expand details
Last updated
Jul 1, 2023
Main use of this computer
For home and private use
Operating system
macOS 15 Sequoia
On-device encryption
Not applicable
Device sign-in security
    • Account password
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Account Control (UAC)
Always notify
Smart App Control
Off
Network firewall
N/A
Router and network details
idk bruh
Real-time protection
Kaspersky Premium
Device firewall
Other - Internet Security (3rd-party)
Custom security settings
Default Deny Intrusion Prevention - Restrictions on trusted applications that are not system based. Blocked tampering of Kaspersky.
Periodic malware scanners
NPE, Emisoft.
Malware sample testing
I do not participate in malware testing
Environment for malware testing
N/A
Browsers and extensions
Ublock Origin, Kaspersky Password Manager.
Secure DNS
N/A
Desktop VPN
Kaspersky VPN
Password and passkey manager
Kaspersky Password Manager
File and photo backups
N/A
System recovery
EaseUS Todo Backup
Usage and exposure
    • Visiting familiar websites
    • Visiting unknown or untrusted websites
    • Making audio/video calls
    • Online shopping and card payments
    • Downloading software and files from reputable sites
    • Downloading files from unknown or untrusted sources
    • Gaming
    • Gaming with third-party mods
    • Streaming audio/video content from trusted sites or paid subscriptions
    • Streaming from untrusted sites
    • Coding and development
    • Downloading malware samples
Computer specs
Corsair Vengeance i8200 - RTX 4090, i9-14900k, 64gb RAM, 4TB SSD.
Notable changes
Changed Checkpoint to Kaspersky Premium
Default Deny setup with Kaspersky, Hardened Intrusion Prevention for Trusted Applications (Cannot Tamper with Kaspersky)
Feedback preference

Detailed suggestions and alternatives welcome

  • Something that is always recommended is to have UAC: Always Notify.
  • I would say replace Emisoft with Kaspersky Virus Removal Tool. (NPE and KVRT are the best)
  • For password manager move to a third party one not connected to an AV vendor such as Bitwarden or 1Password. (It's a hussle when you move to a new AV product and tranfer all your passwords.)
 
  • Something that is always recommended is to have UAC: Always Notify.
  • I would say replace Emisoft with Kaspersky Virus Removal Tool. (NPE and KVRT are the best)
  • For password manager move to a third party one not connected to an AV vendor such as Bitwarden or 1Password. (It's a hussle when you move to a new AV product and tranfer all your passwords.)
Going to switch back to Kaspersky afterwards, there is no need for KVRT if I have kaspersky lol. Checkpoint also uses Kaspersky's engine.

Once Kaspersky ends I also plan on moving to Bitwarden.
 
Last edited by a moderator:
Given the fact that you surf and download files from unknown and shady websites, and the huge deal that you download malware samples for testing, you may be at risk.
  • You shouldn't be switching antiviruses like you are (I have this one, then going to this one, when trial ends going back to other one). You should stick to one solid solution for your security and your system's stability.
  • You should define ASAP a system recovery solution and a file backup solution. Your surfing habits tend to infect machines, therefore you should be prepared for the worst.
 
Given the fact that you surf and download files from unknown and shady websites, and the huge deal that you download malware samples for testing, you may be at risk.
  • You shouldn't be switching antiviruses like you are (I have this one, then going to this one, when trial ends going back to other one). You should stick to one solid solution for your security and your system's stability.
  • You should define ASAP a system recovery solution and a file backup solution. Your surfing habits tend to infect machines, therefore you should be prepared for the worst.
I dont engage in malware testing - I just like get a file and put it into sandboxes if someone suspects something as being infected.
Also I do plan on sticking to one solution once the trial ends, its Kaspersky for like 8 months then something else once that ends.
 
I used to avoid system backups for years, but you would not believe how useful it can be, especially when you are out of time.
I can reinstall Windows plus install everything within 2 hours, but it will not beat 1 min system restore, when really really needed.
 
I used to avoid system backups for years, but you would not believe how useful it can be, especially when you are out of time.
I can reinstall Windows plus install everything within 2 hours, but it will not beat 1 min system restore, when really needed.
How do you create restore points?
 
How do you create restore points?
EaseUS Todo Backup Free, but the smaller the system partition is, the better. You should keep the system partition separate from your data, keep data backed up using a cloud service.
 

Attachments

  • capture_07142023_212530.jpg
    capture_07142023_212530.jpg
    117.9 KB · Views: 246
How do you create restore points?

EaseUS Todo Backup Free, but the smaller the system partition is, the better. You should keep the system partition separate from your data, keep data backed up using a cloud service.
You should try the Hasleo Backup Suite. I started using it recently, and I posted about it on the HBS thread.
 
Added SWH (Default Settings)
Changed Checkpoint Harmony to Kaspersky Premium
Kaspersky Setup - Default Deny, Isolated Browsers, Non System Applications cannot tamper with Kaspersky (Intrusion Prevention)
File AV set to scan all files with deep heuristics.
UAC Set to "Always Notify"
Added System Restore/Backup Software
Also I am now starting to use Intellix and Kaspersky Opentip apon recieving files that arent trusted by Intrusion Prevention.
 
Added SWH (Default Settings)
Changed Checkpoint Harmony to Kaspersky Premium
Kaspersky Setup - Default Deny, Isolated Browsers, Non System Applications cannot tamper with Kaspersky (Intrusion Prevention)
File AV set to scan all files with deep heuristics.
UAC Set to "Always Notify"
Added System Restore/Backup Software
Also I am now starting to use Intellix and Kaspersky Opentip apon recieving files that arent trusted by Intrusion Prevention.

"If you've applied @harlan4096 's configuration regarding Kaspersky, SWH is overkill."
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top