Windows Hardening Guide | 2024 Edition

Поделиться
HTML-код
  • Опубликовано: 16 сен 2024

Комментарии • 67

  • @KenHarrisio
    @KenHarrisio  18 дней назад +12

    I intended this video to be 20 minutes, but it turned into an hour long yap fest. If you're looking for one thing on the list for high impact, I recommend checking out one of the firewalls I mentioned.

    • @billlee5679
      @billlee5679 17 дней назад +4

      I love listening to your inference and reference even to the tiniest trivial things. You have raised certain topics on malware boot kit, rootkit, rnalicious scamming software and devices, without your elaboration and illustration, we fans won't know any wherefores. I could just see and hear your continual coherence in presentation of your whole channel. Logical steps allow us to mitigate in times of crash and crisis, so your videos could be good companion with us 24/7. Thank you so much!!!

  • @michaelbennett9127
    @michaelbennett9127 15 дней назад +3

    I learned so much. Waffle away mate. A great, comprehensive tutorial. Thank you.

  • @Upgrayedddd
    @Upgrayedddd 17 дней назад +4

    You weren't kidding about the chatter. Subscribed

  • @CedroCron
    @CedroCron 17 дней назад +2

    I'm the same as you with what I use for my own windows installs, for family I use Bitdefender because I find with everything turned on it keeps my parents and in-laws safe because they click on stuff they shouldn't. I also like that I can manage their settings from my Bitdefender control panel. Also tip, turn off the auto-renewal and wait for the emails offering you a cheaper renewal. I get the 10 license super cheap.

  • @UltraZelda64
    @UltraZelda64 14 дней назад +2

    Here's a much easier solution for "hardening" Windows:
    1. Back up data, wipe system drive, install Linux in its place
    2. Set up a Windows virtual machine containing *only* what you absolutely need
    3. Only use the virtual machine when absolutely necessary; shut down and use the main OS for anything else
    For even better privacy and security, drop the virtual machine and avoid Windows entirely. Can't get much simpler than that.

  • @sayid3856
    @sayid3856 18 дней назад +1

    Great vid as always! Keep up the good work mate! Cheers

  • @JohnnyJazZzZz
    @JohnnyJazZzZz 16 дней назад +2

    Great vid!
    When recall gets forced on me I'm switching OS.

  • @IlIIlIllI
    @IlIIlIllI 16 дней назад +1

    fire video, I love long style videos but you cant please everyone, my advice is clip the important parts and make it a 15-20 minute video, then make an extended version (think of it as a solo podcast) with all the details. Just a thought, have a good day

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      Thanks for the suggestion! I've been strongly considering doing clips (or a clips channel) for people wanting the shorter versions.

  • @steventelfer8186
    @steventelfer8186 17 дней назад +1

    This is exactly what i was looking for! Thank you

  • @supriyochatterjee4095
    @supriyochatterjee4095 16 дней назад +1

    Excellent information, please make a video on how to configure and tuneup Windows Firewall for the maximum security.

  • @RazoBeckett.
    @RazoBeckett. 9 дней назад +1

    "Security is just an illusion!"

  • @drmikeyg
    @drmikeyg 17 дней назад +1

    Thanks Ken, great video.

  • @_idi0tsavant_
    @_idi0tsavant_ 17 дней назад +1

    great information ken. thanks!

  • @tony_montana9999
    @tony_montana9999 15 дней назад +1

    Amazing video. thanks so much

  • @optimizedujjwal1592
    @optimizedujjwal1592 16 дней назад +2

    hey man love u so much great u are big lion heart person brother well done

    • @KenHarrisio
      @KenHarrisio  14 дней назад +1

      Hey brother, I'm glad to see you're still around! God bless!

    • @optimizedujjwal1592
      @optimizedujjwal1592 14 дней назад +1

      @@KenHarrisio 🥰

  • @nubfaceforthelose
    @nubfaceforthelose 12 дней назад +1

    I assume this applies to Windows 10 also until it dies? How does the CTT script go with defender and portmaster and having tron for emergency sound? As always thanks for the videos man.

    • @KenHarrisio
      @KenHarrisio  10 дней назад +1

      Yeah, I've tested this and these tweaks work 1:1 across 10 and 11. The only difference will be some slight differences in Group Policy between the two versions. CTT's script seems to work well with Defender and Portmaster. I've seem some reports that some of the tweaks can cause issues with wifi, but I've not seem anyone talk about issues with ethernet. I haven't tested Tron before, so I can't speak to the compatibility of it with everything else.
      Thanks for supporting the channel!

  • @pashachoo
    @pashachoo 18 дней назад +1

    thank you proffesor

  • @shinjonmusic
    @shinjonmusic 16 дней назад +1

    Thank you for making a security educational video about security. Can you make a video about online banking security?

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      Sure thing, I'll add it to the list!

  • @lotuschamp7796
    @lotuschamp7796 18 дней назад +2

    You reckon the Microsoft Activation Scripts (MAS) safe for use, or has there been any reports of underhand mischief at play?

    • @Sarah-vs-Hagar
      @Sarah-vs-Hagar 18 дней назад

      Microsoft is never safe when you have Gates using his worldview to change the lives of people. He is committed to Jesuitism. Watch the new video by Adullam Films called American Jesuits to see how Georgetown is behind the scenes as well,

    • @KenHarrisio
      @KenHarrisio  18 дней назад +2

      As long as you download it from the official site/repo, you should be good. The people who say they've been infected by it got it from a shady source. Like any popular repo, bad actors will clone these to try to get people to download malware and sometimes they get the repo listed on Google. With how many people use the tool, I think people would catch malicious changes right away.

  • @F-Bomb313
    @F-Bomb313 18 дней назад

    nice, thanks for this video man, great information

  • @yosyh
    @yosyh 10 дней назад +1

    Hi, will "Windows Firewall Control" work with DefenderUI or ConfigureDefender?

    • @KenHarrisio
      @KenHarrisio  7 дней назад

      Yeah, it'll work well with both options. The firewall just makes it easier to allow/deny what gets access to the internet. I've used Simplewall for years (similar to WFC) and it works great with hardening tools.

    • @yosyh
      @yosyh 7 дней назад

      @@KenHarrisio Thanks,
      Thanks,
      I'll try.
      DefenderUI or ConfigureDefender?

    • @KenHarrisio
      @KenHarrisio  6 дней назад

      @@yosyh The abilities of each are close enough to each other, so I would give preference to ConfigureDefender since it's open source.

  • @lussor1
    @lussor1 18 дней назад +3

    You missed tweaking privacy tools like Chris Titus wintool

    • @KenHarrisio
      @KenHarrisio  18 дней назад +1

      Damn, good point. The ISO creator he added is solid.

    • @Upgrayedddd
      @Upgrayedddd 17 дней назад

      Ultimate tweaker or does he have multi tools?

    • @lussor1
      @lussor1 17 дней назад

      @@Upgrayedddd check it yourself

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      Chris has build a ton of features into his Windows utility. I recommend giving it a go to see what you think of it.

    • @Upgrayedddd
      @Upgrayedddd 14 дней назад

      @@lussor1 I have no way of checking which tools you think are good or whether Titus worked on other tools on the download site that's full of other programs. Word of mouth is still one of the best ways to check on something, especially small projects without an advertising budget. When you like one of those projects, the idea is to help promote it by telling other people about it, especially when they ask.

  • @epic_journey.
    @epic_journey. 12 дней назад +1

    Defender ui vs configure defender which is better?

    • @KenHarrisio
      @KenHarrisio  10 дней назад +1

      As far as what they accomplish, they have similar capabilities. I would be more willing to recommend DefenderUI if the app was open source. I'm becoming more hesitant these days to recommend something that isn't open source with a large user base or a closed source program with a publicly known team.

  • @Alex13312
    @Alex13312 16 дней назад +1

    Are you using both simplewall and portmaster?

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      Yeah, I've been doing it for a few years and they work great together!

  • @robyee3325
    @robyee3325 15 дней назад +1

    should you spin up a vm before clicking on a link?

    • @KenHarrisio
      @KenHarrisio  14 дней назад +1

      You could if you want to. It might be a good idea if you're suspicious of it. A great encrypted DNS provider and uBlock Origin can alleviate a lot of the risk.

    • @robyee3325
      @robyee3325 14 дней назад +1

      @@KenHarrisio thanks for replying!

  • @TacticalBoss
    @TacticalBoss 16 дней назад +1

    Hey could you do one for windows 11 please? thank you

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      The tweaks here can be used on both W10 and W11. I use these tweaks personally between the editions and they work well. Group Policy used to have some privacy differences between 10/11, but they are mostly the same now.

  • @ognjenjakovljevic494
    @ognjenjakovljevic494 17 дней назад +4

    You are blocking all 3rd party malware, what about windows malware like copilot and other malicions microsoft intents?

    • @mohammadiaa
      @mohammadiaa 16 дней назад +1

      Then don't use windows lawl

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      Group Policy is the method I use to block it, along with the telemetry blocking in Simplewall and Portmaster. It's safe to operate with the presumption that MS has the ability to see what you're doing on Windows regardless.

  • @gtm5650
    @gtm5650 17 дней назад +1

    Whats your take on Windows build in VPN?

    • @KenHarrisio
      @KenHarrisio  14 дней назад

      The built in Windows option is okay as long as you use IPsec. The ability to use PPTP is still there which hasn't been safe to use for years. A VPN app is my preferred choice, since you'll get to choose either Wireguard or OpenVPN.

  • @erikferguson71
    @erikferguson71 17 дней назад +1

    Just enable the Linux firewall and off you go into the wild blue yonder!!!

  • @masztos9573
    @masztos9573 18 дней назад +1

    Cool chef

  • @hyiping5926
    @hyiping5926 18 дней назад +5

    Only windows hardening you need is Linux

    • @Upgrayedddd
      @Upgrayedddd 17 дней назад +1

      Unless you're white and male though, right?

  • @knofi7052
    @knofi7052 17 дней назад +2

    Just install Linux!😉

  • @togwam
    @togwam 16 дней назад +1

    Tip #1: Avoid using Windows altogether if you value privacy and security

  • @ТоварищКамрадовСоциалистКоммун

    I'm sure your video is great, and looking at the content timestamps I realize it is. BUT.
    It's too long. With all the respect to you and your channel I wouldn't watch it right here right now. Later, and probably not all at once.
    The best idea I guess would split it into parts, and it's still not too late )

    • @KenHarrisio
      @KenHarrisio  18 дней назад +1

      That a fair point. I could have split it into to parts but I figured most people would watch the two or three sections they thought applied most for them.

    • @JakeNach
      @JakeNach 18 дней назад +1

      I highly disagree with this. Especially when he puts all the timestamps in the video, you can just click that and skip to whatever you need to see, instead of having to watch part 2 or 3 to find what you're looking for.

    • @ТоварищКамрадовСоциалистКоммун
      @ТоварищКамрадовСоциалистКоммун 18 дней назад

      Sure you can totally disagree. But think about content creator and YT algorithms. Shorter videos will be watched from beginning to the end without jumping, they will probably get more recommendations and more people will come to this channel. I think that Ken deserves it

    • @JakeNach
      @JakeNach 18 дней назад

      @@ТоварищКамрадовСоциалистКоммун Yeah, I guess from an algorithm standpoint you're right.

    • @KenHarrisio
      @KenHarrisio  18 дней назад +3

      I appreciate the support as always. This isn't something most people would say but at least for the time being, channel growth isn't something I'm working on. I like making mostly long niche videos, so they don't get much for views. My channel is at a size where I have enough time to still comment with most people which is a plus.