Vether
Product · 12 modules · Windows 10 / 11 x64

Everything that hardens Windows, already wired in.

Twelve modules, over 1,200 options. Each does one precise, measurable, reversible thing. Detailed module-by-module overview.

Module 01· Dashboard

Home

Aggregated privacy score in real time, protection status, shortcuts to the critical actions. You see at a glance what's locked down and what still leaks.

  • Privacy score 0–100 computed from 88 system indicators
  • Global enable/disable of protection
  • Inventory of active fingerprints (hardware, network, browser)
  • Automatic detection of inconsistencies between identifiers
  • Direct access to the 11 other modules with status (active/disabled/partial)
Module 02· Antidetect Firefox

Browser

Hardened Firefox Portable ESR, isolated multi-account profiles, deeply rewritten fingerprint. Every session looks like a different machine to websites.

  • 25+ fingerprint parameters customizable per profile (User-Agent, resolution, GPU, timezone, language)
  • 7 rebranded native extensions (uBlock, NoScript, FoxyProxy, Cookie AutoDelete, LocalCDN, Privacy Badger, Antidetect)
  • Spoofing of 40+ JavaScript APIs (Canvas, WebGL, AudioContext, fonts, geolocation, devices)
  • Cookie Collector — pre-fills each profile with a realistic browsing history
  • Bulk Profile Creator — 50+ consistent profiles in one click
  • Local REST API (port 35000) to drive Selenium / Puppeteer / Playwright
Module 03· 77 spoofed identifiers

Hardware

Motherboard, BIOS, UUID, HWID, MAC, chassis and GPU serial numbers. Everything that makes your machine unique to anti-fraud fingerprints becomes volatile.

  • 77 hardware identifiers mapped across 4 layers (registry, WMI shadow, driver filter, SMBIOS override)
  • Rotating MAC on every network interface (Ethernet, Wi-Fi, Bluetooth)
  • Regenerable Machine GUID, Microsoft Hardware Hash, Windows Activation ID
  • Spoofing of motherboard, BIOS, chassis and disk serials (IOCTL)
  • GPU profile and machine certificates masked
  • Full one-click restore — no risk of bricking
Module 04· 152 hardening options

Windows

Take back control over everything Microsoft set behind your back. From Cortana to Windows Recall, through Defender, SmartScreen, Bing and the biometric services.

  • 152 Windows 10 / 11 hardening options (registry, services, GPO, policies)
  • Disable Windows Recall, Copilot, Spotlight, Consumer Experience
  • Microsoft Defender, SmartScreen, indexing, biometrics under granular control
  • App-Device Access permission policies (camera, mic, contacts, location)
  • Settings / passwords / Wi-Fi sync individually disableable
  • Bing, web search, suggestions, ads, Windows Insider neutralized
Module 05· 184 vectors cut

Telemetry

Systematic shutdown of everything that reports back to Microsoft. Services, scheduled tasks, DNS hosts, firewall, route table, IFEO — every layer at once.

  • 184 blocking options, exhaustive coverage (100% implemented)
  • 120 registry keys disabled (DiagTrack, AppCompat, Customer Experience, Error Reporting…)
  • 30 Windows services stopped and disabled at startup
  • 105 scheduled tasks neutralized (Microsoft Compatibility Appraiser, Office Telemetry…)
  • 200+ reporting domains blocked via hosts file + route table (60+ IPs blackholed)
  • Blackbird integration (17 additional registry keys) + ETW/WMI protection
Module 06· VeraCrypt + sanitization

Disks

Full system encryption, hidden containers with plausible deniability, multi-pass forensic wiping. Built on VeraCrypt — the most thoroughly public audit in the industry.

  • Full system disk encryption (AES-256, AES-Twofish-Serpent cascade optional)
  • Encrypted portable volumes (USB, archives) with SHA-256 / Whirlpool / Streebog hash
  • Hidden volumes with plausible deniability (outer + inner key indistinguishable)
  • 57 sanitization methods (NIST 800-88, DoD 5220.22-M, Gutmann, ATA Secure Erase, NVMe Sanitize)
  • Dead Man's Switch — unmount + clear DNS + clipboard + recent docs in an emergency
  • Pagefile wipe at shutdown, NTFS metadata (MFT, slack, USN journal)
Module 07· 63 items + deep OPSEC

Cleaning

Beyond classic cleaning: removal of the forensic traces CCleaner ignores. Shellbags, UserAssist, BAM/DAM, Jump Lists — the artifacts investigators look for first.

  • 5 critical OPSEC actions (Shellbags, UserAssist ROT13, BAM/DAM, Jump Lists, Pagefile Wipe)
  • 63 cleaning items sorted by category (NTFS, registry, browsers, persistence)
  • Fast / secure (1 pass) / forensic mode (3 passes + 26× rename + SQLite VACUUM)
  • Chrome, Firefox, Edge caches — history, downloads, autofill, password cache
  • USB, RDP, ActivitiesCache (Timeline), MUICache, WordWheelQuery traces
  • DISM Cleanup-Image, %TEMP%, Recycle Bin, Delivery Optimization, BranchCache
Module 08· Fictional personae

Identity

Generation of consistent identities: civil details, contact, payment, disposable e-mail, profile picture, clean metadata. Everything you need to separate an activity.

  • FR identity generator (consistent first name, last name, address, phone, date of birth)
  • Built-in temporary e-mails (disposable address + inbox)
  • Bank card generator (valid Luhn algorithm, Visa / Mastercard / Amex / Discover)
  • Password generator (8–64 characters, configurable classes)
  • Metadata cleaning (photo EXIF, Office docProps, PDF metadata)
  • Companion tools: RealtimeVoiceChanger, Splitcam (virtual webcam), GPG4win, Monero wallet
Module 09· 52 options + 4 scans

Security

System security layers beyond Defender: Credential Guard, LSA Protection, WDigest, NTLMv2, SMB signing, DEP, SEHOP, SMBv1 blocking, USB lockdown, Schannel.

  • 31 system hardening options (USBSTOR, SMBv1, PowerShell 2.0, AutoPlay, Remote Assistance, Clipboard history)
  • 21 Schannel options — TLS 1.0–1.3, ciphers (RC4, DES, 3DES, NULL), hashes (MD5, SHA1), DH/RSA min bits
  • Credential Guard + LSA Protection (RunAsPPL), WDigest cleartext blocked, NTLMv2 enforced
  • 4 system scans: malware, leaks & spying (netstat), integrity (sfc /scannow + DISM), individual file
  • Configurable Spectre / Meltdown mitigations (OS kernel + Hyper-V)
  • Defender ASR rules (17 GUIDs), system DoH, security event auditing
Module 10· Mullvad VPN, 46 countries

VPN

Built-in VPN based on Mullvad — no email required to sign up, payment in cryptocurrency or cash possible, WireGuard exclusively, kill-switch always on.

  • 46 countries (ZA, DE, AR, AU, AT, BE, BR, CA, CL, CH, JP, SE, US, FR, GB…)
  • WireGuard only — ChaCha20-Poly1305, Curve25519, BLAKE2s, optional post-quantum
  • Kill-switch always on, full traffic block on disconnect + Lockdown Mode
  • Configurable multi-hop (double VPN) — separate entry and exit countries
  • Windows Split Tunneling — exclusion per individual .exe
  • Optional DAITA (Defence Against AI Traffic Analysis) — resists network pattern analysis
Module 11· 23 + 24 isolation options

VirtualBox

Built-in VM sandbox with VBoxManage orchestration: disposable VMs, anti-detection, anti-forensics, auto-revoked snapshots, strict network isolation.

  • 23 host isolation options (strict NAT, LAN/bridge blocking, shared folders, clipboard, drag-drop)
  • 24 anti-forensic options (auto snapshots, immutable disk, UUID reset, cleaned logs)
  • Disposable VMs — ephemeral clone + baseline snapshot + automatic rollback
  • Devices: USB, audio, webcam, Bluetooth, serial/parallel, VRDE — individually disableable
  • VM anti-detection (SMBIOS spoof, random MAC, CPUID hooks) to resist Pafish tests
  • Host cleaning: VBox artifacts, registry, orphaned network adapters
Module 12· 88 data points · risk score

Information

Full audit of what can be learned from your machine in an instant. Identifies exposed identifiers, computes a weighted risk score, flags inconsistencies.

  • 88 data points collected in parallel (WMI, registry, network, processes, WinForms)
  • Exposed identifiers: machine UUID, Microsoft HWID, user SID, disk serials
  • Network fingerprint: public IP, MAC, DNS, route table, gateway, MTU, active VPN
  • Virtual environment detection (Hyper-V, VBox, VMware, hypervisor)
  • DNS / WebRTC / IPv6 leak tests — diagnosing the layers that bypass the VPN
  • Weighted Risk Score 0–100, qualitative risk level (low, moderate, high, critical)