Hardening
Wi-Fi & Router Security Hardening
Step-by-step router configuration guides: WPA3 personal/enterprise, DNS-over-HTTPS (DoH), isolated guest networks, and WPS disabling.
Mandate WPA3-Personal or WPA2/WPA3 Mixed mode with protected management frames.
WPS PINs can be brute-forced within hours using Reaver or PixieWps.
Prevents compromised smart thermostats or cameras from pivoting to laptops.
Configure Quad9 (9.9.9.9) or Cloudflare (1.1.1.2 malware-blocking) upstream.
Router administration interface should never be accessible from the public internet.
Prevents malware inside the LAN from autonomously opening inbound firewall ports.
This module is guided content rather than a processing tool. It walks you through steps on the systems you already use, and nothing about your setup is sent to us.
No single tool makes an account or a device secure. This module reduces one specific category of risk. It does not detect malware already running on your device, it cannot recover data you lose the key to, and it does not replace keeping software updated and using unique credentials everywhere.
If your device itself is compromised, anything you type into any tool — including this one — can be observed. Treat device hygiene as the foundation everything else sits on.