# Consurgam Schutz fuer Windows / Consurgam protection for Windows (version 1) # Source: consurgam.com/schutz - Sends nothing to Consurgam, downloads nothing. # # What it does: # 1. DNS over HTTPS with Cloudflare for Families (blocks adult and malware sites), IPv4 and IPv6, # no fallback to unencrypted DNS (Windows 11; on Windows 10 only plain DNS). # 2. Sets these DNS servers on every active network adapter. # 3. Browser policies (HKLM): no InPrivate/Incognito/private windows, no guest mode, secure DNS fixed # to Cloudflare for Families, SafeSearch. Edge, Chrome, Brave, Firefox. # 4. Checks the result: a Cloudflare test domain must resolve to 0.0.0.0. # Run it in "Terminal (Admin)". Safe to run again (idempotent). To undo: consurgam-windows-entfernen.ps1 # The key: whoever knows the administrator password can undo this. Your anchor keeps it. & { $ErrorActionPreference = 'Stop' $doh = 'https://family.cloudflare-dns.com/dns-query' $dns = @('1.1.1.3', '1.0.0.3', '2606:4700:4700::1113', '2606:4700:4700::1003') $test = 'nudity.testcategory.com' # Cloudflare test domain in the adult category, harmless # --- 0. Administrator? --- $ich = [Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent() if (-not $ich.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { Write-Host 'Bitte als Administrator starten: Rechtsklick auf Start > Terminal (Administrator).' -ForegroundColor Yellow Write-Host 'Please run as administrator: right-click Start > Terminal (Admin).' -ForegroundColor Yellow return } # --- 1. Register DNS over HTTPS (Windows 11 / Server 2022+) --- $mitDoh = [bool](Get-Command Add-DnsClientDohServerAddress -ErrorAction SilentlyContinue) if ($mitDoh) { foreach ($a in $dns) { $da = Get-DnsClientDohServerAddress -ServerAddress $a -ErrorAction SilentlyContinue if ($da) { Set-DnsClientDohServerAddress -ServerAddress $a -DohTemplate $doh -AllowFallbackToUdp $false -AutoUpgrade $true | Out-Null } else { Add-DnsClientDohServerAddress -ServerAddress $a -DohTemplate $doh -AllowFallbackToUdp $false -AutoUpgrade $true | Out-Null } } Write-Host '[1/4] DNS ueber HTTPS eingerichtet / DNS over HTTPS registered' } else { Write-Host '[1/4] Dieses Windows kennt kein DNS ueber HTTPS (Windows 10). Es filtert trotzdem, aber unverschluesselt.' -ForegroundColor Yellow Write-Host ' This Windows has no DNS over HTTPS (Windows 10). It still filters, unencrypted.' -ForegroundColor Yellow } # --- 2. DNS servers on all active adapters --- $adapter = @(Get-NetAdapter | Where-Object { $_.Status -eq 'Up' }) foreach ($n in $adapter) { Set-DnsClientServerAddress -InterfaceIndex $n.ifIndex -ServerAddresses $dns } Clear-DnsClientCache Write-Host ("[2/4] DNS gesetzt auf {0} Adapter(n) / DNS set on {0} adapter(s): {1}" -f $adapter.Count, (($adapter | ForEach-Object Name) -join ', ')) # --- 3. Browser policies --- function Setze([string]$pfad, [hashtable]$werte) { if (-not (Test-Path $pfad)) { New-Item -Path $pfad -Force | Out-Null } foreach ($k in $werte.Keys) { $v = $werte[$k] $typ = if ($v -is [string]) { 'String' } else { 'DWord' } New-ItemProperty -Path $pfad -Name $k -Value $v -PropertyType $typ -Force | Out-Null } } Setze 'HKLM:\SOFTWARE\Policies\Microsoft\Edge' @{ InPrivateModeAvailability = 1; BrowserGuestModeEnabled = 0; ForceGoogleSafeSearch = 1; ForceBingSafeSearch = 2 DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh } Setze 'HKLM:\SOFTWARE\Policies\Google\Chrome' @{ IncognitoModeAvailability = 1; BrowserGuestModeEnabled = 0; SafeSitesFilterBehavior = 1; ForceGoogleSafeSearch = 1 DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh } Setze 'HKLM:\SOFTWARE\Policies\BraveSoftware\Brave' @{ IncognitoModeAvailability = 1; BrowserGuestModeEnabled = 0; SafeSitesFilterBehavior = 1; ForceGoogleSafeSearch = 1 DnsOverHttpsMode = 'secure'; DnsOverHttpsTemplates = $doh } Setze 'HKLM:\SOFTWARE\Policies\Mozilla\Firefox' @{ DisablePrivateBrowsing = 1; PrivateBrowsingModeAvailability = 1 } Setze 'HKLM:\SOFTWARE\Policies\Mozilla\Firefox\DNSOverHTTPS' @{ Enabled = 1; ProviderURL = $doh; Locked = 1; Fallback = 0 } Write-Host '[3/4] Richtlinien fuer Edge, Chrome, Brave, Firefox gesetzt (Browser neu starten) / Browser policies set (restart browsers)' # --- 4. Check --- try { $ip = @(Resolve-DnsName -Name $test -Type A -DnsOnly -QuickTimeout | Where-Object { $_.IPAddress } | ForEach-Object IPAddress) } catch { $ip = @() } if ($ip -contains '0.0.0.0') { Write-Host "[4/4] OK: $test -> 0.0.0.0. Der Filter wirkt. / The filter works." -ForegroundColor Green } else { Write-Host ("[4/4] Achtung: {0} -> {1}. Erwartet 0.0.0.0. VPN aktiv oder anderer DNS? / Check failed, expected 0.0.0.0." -f $test, ($ip -join ', ')) -ForegroundColor Yellow } Write-Host 'Jetzt: eigenes Konto auf Standardbenutzer stellen, Administrator-Passwort behaelt dein Anker.' Write-Host 'Next: make your own account a standard user; your anchor keeps the administrator password.' }