Hi guys! I'm back with a new guide, this time giving some tips of how to harden Low Restricted group.
Without further delay, these are the steps to follow:
1.- Go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention, and set:
This may be a bit aggressive, so for newbies and / or standard users, probably better to leave Trust digitally signed applications enabled. That will lead to get less blocking in legit applications.
2.- Go to Settings -> Security Settings -> Advanced Settings -> Exclusions and actions on object detections, and set:
3.- Now We are going to hard a bit also Trusted group, so go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention -> Manage Applications.
Once Manage Applications window is open, select Trusted group with Your mouse pointer, then 1 click on mouse right button -> Details and Rules, and in the new window, go to tab Rights:
In this new window We have to change the selected rights in orange color, to do so, again just select with Your mouse pointer in Shut down Microsoft Windows (1), then 1 click on the small arrow down on the right (2), then select Ask User (3), and later repeat the same to enable Log events (4):
Repeat the same to change the remaining orange rights shows in previous capture, once ended, click on Save (and allowsaving the changes in the next Kaspersky prompt window).
4.- And finally going to harden Low Restrictedgroup. We are going to repeat all the steps in previous point to harden Trusted group, but this time with Low Restricted group:
Go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention -> Manage Applications.
Once Manage Applications window is open, select Low Restricted group with Your mouse pointer, then 1 click on mouse right button -> Details and Rules, and in the new window, go to tab Rights:
And then set all the changes in the rights inside red squares, don’t forget to click on Save once you're done.
5.- Additionally and to finish, I also added some restrictions in Intrusion Prevention -> Manage Resources:
Added my user folder (Windows account located in C:\Users\<Your account>\) with those hardened restrictions, if you don’t know how to do so, check my previous guide, also in this community section:
Hi guys! I'm back with a new guide, this time giving some tips of how to harden Low Restricted group.
Without further delay, these are the steps to follow:
1.- Go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention, and set:
This may be a bit aggressive, so for newbies and / or standard users, probably better to leave Trust digitally signed applications enabled. That will lead to get less blocking in legit applications.
2.- Go to Settings -> Security Settings -> Advanced Settings -> Exclusions and actions on object detections, and set:
3.- Now We are going to hard a bit also Trusted group, so go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention -> Manage Applications.
Once Manage Applications window is open, select Trusted group with Your mouse pointer, then 1 click on mouse right button -> Details and Rules, and in the new window, go to tab Rights:
In this new window We have to change the selected rights in orange color, to do so, again just select with Your mouse pointer in Shut down Microsoft Windows (1), then 1 click on the small arrow down on the right (2), then select Ask User (3), and later repeat the same to enable Log events (4):
Repeat the same to change the remaining orange rights shows in previous capture, once ended, click on Save (and allow saving the changes in the next Kaspersky prompt window).
4.- And finally going to harden Low Restricted group. We are going to repeat all the steps in previous point to harden Trusted group, but this time with Low Restricted group:
Go to Settings -> Security Settings -> Advanced Protection -> Intrusion Prevention -> Manage Applications.
Once Manage Applications window is open, select Low Restricted group with Your mouse pointer, then 1 click on mouse right button -> Details and Rules, and in the new window, go to tab Rights:
And then set all the changes in the rights inside red squares, don’t forget to click on Save once you're done.
5.- Additionally and to finish, I also added some restrictions in Intrusion Prevention -> Manage Resources:
Added my user folder (Windows account located in C:\Users\<Your account>\) with those hardened restrictions, if you don’t know how to do so, check my previous guide, also in this community section:
Implementing Protected Folders via Manage Resources + Anti-Exe / Default Deny
Feel free to ask questions and / or doubts!
Thanks all folks!!!! ?