View Full Version : EMET, what's your thoughts?
moontan
November 24th, 2010, 03:53 PM
i'm trying out EMET.
so far it seems like a good security app, with very minimal system impact.
i feel a little naked using only Shadow Defender.
sure, all the nasties i might've picked up disappear on reboot but i'd like a little protection between reboots. ;)
what do you folks think about EMET?
Boost
November 24th, 2010, 04:10 PM
MBAM free + Hitman Pro :thumb:
IMO your good enough with these 2. Your slowly gonna pile on the software thats really not needed ;)
moontan
November 24th, 2010, 04:50 PM
@ Boost:
-{ Quote: "Your slowly gonna pile on the software thats really not needed" }-
yeah, i would hate for that to happen. ;)
but i see you are using real time protection (Geswall) with Rollback RX!
shouldn't Rollback RX be enough? :)
Boost
November 24th, 2010, 04:53 PM
-{ Quote: "@ Boost:
yeah, i would hate for that to happen. ;)" }-
It's a Wilders paranoia that runs rapid around here,it's quite laughable :argh:
Boost
November 24th, 2010, 04:55 PM
-{ Quote: "@ Boost:
yeah, i would hate for that to happen. ;)
but i see you are using real time protection (Geswall) with Rollback RX!
shouldn't Rollback RX be enough? :)" }-
I've always believed in sandboxing the browser,it's never let me down and Rollback RX is here for any unforseen troubles.Haven't used it yet though!;D
I've got 2 scanners: HitmanPro + Malwarebytes thats it!
J_L
November 24th, 2010, 05:00 PM
It's a great security tool for hardening programs. Uses no resources.
moontan
November 24th, 2010, 05:16 PM
tnx folks.
i'll keep using it until Geswall 3.0 arrives. :)
moontan
November 25th, 2010, 11:35 AM
so far i'm liking EMET.
i'm no expert but i think this is based on policy restrictions, a little bit like Geswall.
there some arcane knowledge in EMET, like DEP or SEHOP which some folks here have played with but that's getting a little too technical for me.
EMET is easy to figure out and configure but there's more granularity available for those who wish.
-
the few reviews of EMET i've read are positives.
anyway, it's free and it's from Microsoft.
how bad could it be? :P
Jav
November 25th, 2010, 02:02 PM
For people who use EMET and Chromium/Chrome/Iron and etc: http://blog.chromium.org/2010/11/compatibility-issues-with-emet.html
BoerenkoolMetWorst
November 25th, 2010, 02:06 PM
-{ Quote: "For people who use EMET and Chromium/Chrome/Iron and etc: http://blog.chromium.org/2010/11/compatibility-issues-with-emet.html" }-
The latest version of EMET, out since a few days, fixes this compatibility issue.
Noob
November 25th, 2010, 04:20 PM
For US wilders, ENOUGH IS NEVER ENOUGH, we don't know that word! ;D ;D :thumb:
safeguy
November 25th, 2010, 04:51 PM
It's easy to use. That's all I can say. Perhaps more Windows users should pick it up...but my guess is that the word "mitigation" scares some from trying it. Mention "mitigation" or anything related to do with "hardening" and they'd say "No, thanks":P
Jav
November 25th, 2010, 07:27 PM
-{ Quote: "The latest version of EMET, out since a few days, fixes this compatibility issue." }-
my bad :(
m00nbl00d
November 25th, 2010, 10:37 PM
I thought EMET was a bit "smarter". I have applied SEHOP quite some time ago, by modifying the registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\DisableExceptionChainValidation (value 0)
I don't know why, but I decided to just check this entry, and there are two. One is obviously the one I created and the other created by EMET. My opinion is that it should be able to detect whether or not this SEHOP entry was or not there already.
I wonder if they override each other? In one system, when I was checking some hardware info with PC Wizard, I could see that SEHOP was being indicated as being disabled. My strong guess is that the two entries override each other.
moontan
November 26th, 2010, 12:52 AM
-{ Quote: "safeguy:
It's easy to use. That's all I can say. Perhaps more Windows users should pick it up..." }-
and later:
-{ Quote: "m00nbl00d:
I thought EMET was a bit "smarter".
" }-
those dont exactly sound like ringing endorsements. ;)
TheKid7
November 26th, 2010, 07:56 AM
I do not have Windows 7 or VISTA. I see that some, but not all of the EMET features are available for Windows XP.
In your opinion, is it worth trying out EMET on one of my Windows XP Pro PC's or should I wait until I eventually get Windows 7?
Thanks in Advance.
m00nbl00d
November 26th, 2010, 08:35 AM
-{ Quote: "I do not have Windows 7 or VISTA. I see that some, but not all of the EMET features are available for Windows XP.
In your opinion, is it worth trying out EMET on one of my Windows XP Pro PC's or should I wait until I eventually get Windows 7?
Thanks in Advance." }-
I am not the "voice", just a voice, but in my own opinion, some of the protection EMET provides sure is better than having none, I'd say. :)
moontan
November 26th, 2010, 09:25 AM
hmmm,
i think i'll slap Geswall back on.
having a security product (EMET in this case) being described as "better than nothing" doesn't inspire confidence. ;)
m00nbl00d
November 26th, 2010, 09:28 AM
-{ Quote: "hmmm,
i think i'll slap Geswall back on.
having a security product (EMET in this case) being described as "better than nothing" doesn't inspire confidence. ;)" }-
Are you sleeping properly? ;D
I wrote
-{ Quote: "some of the protection EMET provides sure is better than having none" }-
EMET won't provide as much protection for XP as it does for Vista and 7. So, some is better than none, right? ;)
moontan
November 26th, 2010, 10:04 AM
-{ Quote: "Are you sleeping properly? ;D" }-
no, i work night shifts. ;)
i was just hoping EMET would be a good substitute for Geswall since EMET uses no resources.
Geswall run real time and hooks the kernel.
not that big of a deal for such a speedy app that's easy to use and give great protection.
Gobbler
November 27th, 2010, 12:56 PM
Does EMET go well with rollback software say RollBack Rx?
BoerenkoolMetWorst
November 27th, 2010, 02:49 PM
-{ Quote: "no, i work night shifts. ;)
i was just hoping EMET would be a good substitute for Geswall since EMET uses no resources.
Geswall run real time and hooks the kernel.
not that big of a deal for such a speedy app that's easy to use and give great protection." }-
You do know EMET is a totally different app, right?
Boyfriend
November 29th, 2010, 09:07 AM
-{ Quote: "Does EMET go well with rollback software say RollBack Rx?" }-
Yes, I work very well with Rollback Rx.
Sully
November 29th, 2010, 10:54 AM
-{ Quote: "i was just hoping EMET would be a good substitute for Geswall since EMET uses no resources" }-
I think you confuse EMET. It is more like a hardening tool that can be used on a per program basis. It is nothing like Geswall. One would use EMET to enhance security.
Sul.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums