What's New
Active Clipboard Monitoring and Inspection for Malware
At the top of the System Overview area on the Home page, is a button that opens the Clipboard Monitor management panel.
Clipboard Monitor watches for newly copied text and automatically scans it using Microsoft Defender's Antimalware Scan Interface (AMSI). It helps protect you from clipboard-based attacks involving malicious commands, scripts, downloaders, or other dangerous text copied from websites, emails, documents, or messages.
You can test AMSI active scan used by the Harden System Security app by copying the scripts mentioned by Microsoft in this demo. Instead of waiting for potentially malicious clipboard content to be pasted or saved in a file and then detected by Microsoft Defender, Harden System Security scans it proactively. If AMSI identifies the content as malicious, the app immediately removes it from the active clipboard, preventing it from being pasted into documents, terminals, or other applications.
The management panel lets you:
-
See whether Clipboard Monitor is currently enabled or disabled.
-
Enable or disable Clipboard Monitor.
-
See whether it is configured to run at startup.
-
Choose whether Clipboard Monitor starts automatically when you sign in to Windows.
When Microsoft Defender identifies copied text as malware, or an antimalware provider reports that it is blocked by administrator policy, Clipboard Monitor removes the detected clipboard content and displays a notification. When available, the notification also identifies the process the content was copied from. The event and any monitoring errors are recorded in the app logs.
Clipboard Monitor is event-driven, so it waits for clipboard changes instead of repeatedly checking the clipboard. It monitors text content only and runs separately from the main app after you enable it, allowing protection to continue after the app window is closed.
Other Changes
-
The SSD temperature in the Windows Widgets or Home page is now able to be displayed on more devices where it would previously be unavailable. - Thanks @IviriusMain for the PR.
-
Improved the app installation compatibility with certain system types and configurations.
-
Improved the download manager's reliability. It now automatically retries downloads that you start forever, that means if in the middle of your important downloads your WIFI stops working or your VPN disconnects or anything else happens, it will successfully resume the download when connectivity comes back. Previously, it would give up after a couple of retries and you'd have to manually resume the downloads which is not ideal if you are away from keyboard.
-
The Harden System Security's Windows service has been hardened, allowing only the app itself to use it. Previously, the only requirement was having administrator privilege, but with this change it is stricter and more secure.
-
The event logs written by the Harden System Security's Windows service in Event Viewer have a better formatting now.
-
Improved localization for all 17 supported languages.
-
In the Winget Management page there is now a new app bundle for the Security category, offering you quick installation for useful security tools and apps from Winget.
-
Improved the Installed Apps Management's page: more types of system apps are now fetched and displayed to you.
-
Improved the Tweaks page: more details of the Windows Recovery Environment (WinRE) is now available to you.