✔ Only download software from official sources (e.g., ninite.com, Microsoft Store, developer GitHub).
✔ Enable Show file extensions in File Explorer – many malware files hide as document.pdf.exe.
✔ Use Standard User Account instead of Administrator daily.
✔ Deploy Application Control (Windows Defender Application Control or simple AppLocker policies).
✔ Scan all USB drives with Windows Defender before opening.