Windows Guide

You can refer to section 5 in Instructions on Hardening Windows (What I Have Learnt So Far)
A developer would run unsigned scripts or apps on their host machine a lot.