FYI: FirewallHardening doesn't include all LOLbins that is abused by malware in it's presets. I have personally manually added every single one and has so far not encountered a single false positive.
@Andy Ful posted he will update the sponsors/Lolbin in a future release. My experience:when on Admin it is easier to block enhanced in H_C and all LoLbins in FW hardening. When running as SUA you can max out H_C also.
Most users should apply only H_C Recommended. In this way, you can get 95% of the protection available via FirewallHardening with 5% of the required effort. Of course, you can fight for the last 5% if you like, but your effort can increase to 100%.
I know people who have many blocks related to explorer.exe.