This is the most hardened workstation that I can get my hands on.
Powering up the BIOS promots for a password. Get passed that and hardrive encryption unlock requires a password. OS level account login comes next. Firewall gets activated with strict outbound and inbound policy. A daemon watched for any outbound connection attempts and allows for whitelist and prevents from blacklist. VPN comes next to encrypt the internet connection. SSH is taken down. Any attempt to probe or gain access gets the source automatically banned via log monitoring in realtime.
2 rootkit scanners, anti-virus, and a system audit with risk scores. Everything tested and working fine.
Yet I’m not satisfied, now I run apps within sandboxes to isolate any exploits coming from social media, metaverse, work, studies, and others. Every sandbox isolates the environment and the damage of an attack.
Next time will be an AI Agent Cybersecurity expert project to monitor kernel and driver level activities and risk.
This site will hold short thoughts, daily observations, technical discoveries, project progress, and records that do not require a full article.