Basic Security overdivine's Security Config

Last updated
Jan 1, 2007
Windows Edition
Enterprise
Security updates
Allow security updates and latest features
User Access Control
Always notify
Real-time security
none (srp default deny)
Firewall security
Microsoft Defender Firewall
Periodic malware scanners
emsisoft eek and avira on demand
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
none
Maintenance tools
Sysinternals Suite
File and Photo backup
OneDrive
System recovery
macrium reflect free
I used to run applocker but not anymore too much to fiddle with. SRP is easier to set up. Now i only a few rules. I used to have a bigger list but i've reinstalled windows and forgot to save them. Until paranoia strikes again (i hope not ) i will use only these rules.
security level is Disallowed (Software will not run, regardless of the access rights of the user.)
I've removed LNK extension from designated file types proprieties so i can run shortcuts. I know i can add extensions but i'm lazy atm.


I have enabled User Account Control: Only elevate executable files that are signed and validated. If you don't work with unsigned software, developing, etc, this is AWESOME.

Annotation1.pngAnnotation2.pngAnnotation3.pngAnnotation4.pngAnnotation5.png

I have windows enterprise and i have device guard on. Windows defender is off.

If i were to use realtime stuff it would be shadow defender, comodo firewall with cs settings and kaspesky av( paid) or windows defender .
I hope paranoia is a thing of the past.
 
Sweet setup. Disabling WD comes down to personal preference, how come you had it turned off? (outta curiosity). Liking the settings you have in this SRP for the enterprise version, looks amazing.

~LDogg