> For the complete documentation index, see [llms.txt](https://epochsec.gitbook.io/daily-activities-best-practices/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://epochsec.gitbook.io/daily-activities-best-practices/general-os-hardening/windows.md).

# Windows

Below are some specific options to improve security of your system. Some specific Windows notes were described in the general section.

* Use Antivirus Software. Either use the Microsoft provided applications (Defender and Firewall), or look into third party solutions.
  * Disable options that are likely already enabled:
    * Location tracking – Tracks your device
    * “Let Apps user Advertising ID” – This tracks activity and provided ads based on the Application activity.
  * Powershell – Ensure your system does not keep older versions. Certain versions can run in parallel. The older a version, the higher the risk.
  * Debloat: Earlier I mentioned a debloater tool to clean off unnecessary software on your Windows Computer. This is called Sycnex.
  * Also mentioned earlier is to use a local account (you will need to create this), versus using your Microsoft account (which is an online account).
  * Do not use automatic login.
  * Do not sign into web browsers with your google account. Also do not sync your account across multiple devices. Applies to web browsers on any OS.
  * Use SysInternals
    * This a tool distributed by Microsoft, and created by Mark Russinovich in 1996)
    * Provided many tools such as process scanning, monitoring services, monitoring logon sessions, port monitoring, and more. There are also tools such as Psinfo|PSkill|PSexec that you can use for a variety of tasks.
