Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 17th, 2010, 10:57 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,420
Default EMET - A new Windows security mitigation toolkit

Hello,

Windows security: a review of Enhanced Mitigation Experience Toolkit (EMET), a whitelist-style security product by Microsoft designed to harden the system by applying a series of mitigation policies to the system and running applications. Finally, a security product worth examining. Do take a look.

http://www.dedoimedo.com/computers/windows-emet.html


Cheers,
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #2  
Old December 17th, 2010, 11:46 AM
ParadigmShift's Avatar
ParadigmShift ParadigmShift is offline
Regular Poster
 
Join Date: Aug 2008
Posts: 195
Default Re: EMET - A new Windows security mitigation toolkit

Your website is great. Thanks for all your hard work.
__________________
MALWARE IS OVER! (If You Want It) Give security a chance. Get to know Windows Security Settings and Policies.
  #3  
Old December 17th, 2010, 12:07 PM
Boyfriend Boyfriend is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Pakistan
Posts: 1,071
Default Re: EMET - A new Windows security mitigation toolkit

Thanks for good review of EMET
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76
  #4  
Old December 17th, 2010, 12:26 PM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,449
Default Re: EMET - A new Windows security mitigation toolkit

Thank you for your hard work.
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #5  
Old December 17th, 2010, 12:29 PM
ruinebabine's Avatar
ruinebabine ruinebabine is offline
Very Frequent Poster
 
Join Date: Aug 2007
Location: QC
Posts: 1,036
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by Boyfriend
Thanks for good review of EMET
Very well written and easy to understand, even for me.

Many of your other pages are also a must read, imho. Am now reading your "Group Policies - Beginners' guide", simple and to the point, and your writing style smoot things off nicely !

Last edited by ruinebabine : December 17th, 2010 at 12:59 PM.
  #6  
Old December 17th, 2010, 01:02 PM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,615
Default Re: EMET - A new Windows security mitigation toolkit

Very well written indeed
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #7  
Old December 17th, 2010, 01:04 PM
Woodgiant
 
Posts: n/a
Default Re: EMET - A new Windows security mitigation toolkit

EMET is looking very interesting and I really like is approach to the security issue I will try it out with VMWARE and throw some malware code at it, Now I will play around

Best Regards and thanks to Mrkvonic.
  #8  
Old December 18th, 2010, 04:04 AM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: EMET - A new Windows security mitigation toolkit

Thanks Mrkvonic
__________________
25 forum posting etiquette tips
  #9  
Old December 19th, 2010, 03:08 AM
blacknight's Avatar
blacknight blacknight is offline
Very Frequent Poster
 
Join Date: Sep 2007
Location: Europe
Posts: 1,596
Default Re: EMET - A new Windows security mitigation toolkit

My question is: it's possible to use this EMET together an HIPS ( I'm using CIS ) or there are some conflict risks ? Someone is trying ?
  #10  
Old December 19th, 2010, 08:39 AM
moontan's Avatar
moontan moontan is online now
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,112
Default Re: EMET - A new Windows security mitigation toolkit

very good review, tnx m8!
__________________
| NoScript || Image for Linux + BootIt Bare Metal |
  #11  
Old December 19th, 2010, 08:42 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,420
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by blacknight
My question is: it's possible to use this EMET together an HIPS ( I'm using CIS ) or there are some conflict risks ? Someone is trying ?

Why would you want to do that?
The whole beauty is that it's transparent.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #12  
Old December 19th, 2010, 04:41 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,820
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by blacknight
My question is: it's possible to use this EMET together an HIPS ( I'm using CIS ) or there are some conflict risks ? Someone is trying ?
Works fine, just don't use EMET on the HIPS.
__________________
  #13  
Old December 19th, 2010, 09:20 PM
Rilla927's Avatar
Rilla927 Rilla927 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 1,620
Default Re: EMET - A new Windows security mitigation toolkit

I installed this yesterday and I have Private Firewall with HIPS and so far okay.
__________________
~Rilla927~
  #14  
Old December 24th, 2010, 03:52 AM
Rilla927's Avatar
Rilla927 Rilla927 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 1,620
Default Re: EMET - A new Windows security mitigation toolkit

I went to microsoft site looking for a 64bit version for my daughter's computer.
__________________
~Rilla927~
  #15  
Old December 24th, 2010, 03:56 AM
Boyfriend Boyfriend is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Pakistan
Posts: 1,071
Default Re: EMET - A new Windows security mitigation toolkit

EMET installer is compatible with x86 as well as x64. You do not need separate installer for 64bit.
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76
  #16  
Old December 24th, 2010, 07:46 AM
Rilla927's Avatar
Rilla927 Rilla927 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 1,620
Default Re: EMET - A new Windows security mitigation toolkit

Oh wow, thank you Boyfriend.
__________________
~Rilla927~
  #17  
Old December 24th, 2010, 10:43 PM
safeguy's Avatar
safeguy safeguy is offline
Frequent Poster
 
Join Date: Jun 2010
Location: Singapore
Posts: 872
Default Re: EMET - A new Windows security mitigation toolkit

Mitigation. I love that word. Seriously.
__________________
Uncertainty is the only certainty there is, and knowing how to live with insecurity is the only security...
  #18  
Old December 24th, 2010, 11:05 PM
brainrb1's Avatar
brainrb1 brainrb1 is offline
Frequent Poster
 
Join Date: Mar 2010
Posts: 436
Default Re: EMET - A new Windows security mitigation toolkit

I have just started using it . I have added Firefox,Foxit reader,IE9,windows media player and Km player to the list.It would be to nice to know what programs/ Configuration Recommendations other people are adding(without problem) so that beginners can learn and add.
__________________
This Too Shall Pass Away
Windows 8×64 bit pro …Laptop. Windows defender(update every 4 hours),Malwarebytes pro...real time .
Windows 8 ×64 bit pro...Windows defender, EXE Radar Pro ...real time.
Pale Moon,Ccleaner.Glary Utilities pro,Hitman pro,XYplorer On demand
  #19  
Old December 24th, 2010, 11:31 PM
Dogbiscuit Dogbiscuit is offline
Frequent Poster
 
Join Date: Jul 2007
Posts: 639
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by brainrb1
It would be to nice to know what programs/ Configuration Recommendations other people are adding(without problem) so that beginners can learn and add.
See here (under Recommended applications to add)
  #20  
Old December 25th, 2010, 01:02 AM
brainrb1's Avatar
brainrb1 brainrb1 is offline
Frequent Poster
 
Join Date: Mar 2010
Posts: 436
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by Dogbiscuit
See here (under Recommended applications to add)
Thanks That was useful.
__________________
This Too Shall Pass Away
Windows 8×64 bit pro …Laptop. Windows defender(update every 4 hours),Malwarebytes pro...real time .
Windows 8 ×64 bit pro...Windows defender, EXE Radar Pro ...real time.
Pale Moon,Ccleaner.Glary Utilities pro,Hitman pro,XYplorer On demand
  #21  
Old December 25th, 2010, 03:17 AM
Rilla927's Avatar
Rilla927 Rilla927 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 1,620
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by Dogbiscuit
See here (under Recommended applications to add)

Thanks, this is exactly what I was looking for
__________________
~Rilla927~
  #22  
Old December 25th, 2010, 03:44 AM
Boyfriend Boyfriend is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Pakistan
Posts: 1,071
Default Re: EMET - A new Windows security mitigation toolkit

Quote:
Originally Posted by Dogbiscuit
See here (under Recommended applications to add)

Thanks you very much I was also looking for this.
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76
  #23  
Old December 25th, 2010, 05:17 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: EMET - A new Windows security mitigation toolkit

Win 7 VM.

Added mbam.exe to EMET protect list and installed the exe killing rogue Security Tool.

At one stage after installing the rogue and a reboot the vm bsod and at reset it booted into a new profile with minimal services running, no graphics or sound.

At a second run where there was no bsod the exe killing rogue still kills everything.

IMO a useless and dangerous tool.
  #24  
Old December 25th, 2010, 08:24 AM
Hugger Hugger is offline
Very Frequent Poster
 
Join Date: Oct 2007
Location: Hackensack, USA
Posts: 1,003
Default Re: EMET - A new Windows security mitigation toolkit

I can't see how to get 'green' under the heading 'Running EMET'.
That whole column is empty.
Any ideas?
Happy Holidays.
Hugger
  #25  
Old December 25th, 2010, 08:45 AM
Boyfriend Boyfriend is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Pakistan
Posts: 1,071
Default Re: EMET - A new Windows security mitigation toolkit

Add a program under EMET and then run that program. A green tick mark will appear in front of program name under 'Running EMET' column.
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:16 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums