EMET - a dummy's guide

Discussion in 'other anti-malware software' started by Feandur, Sep 26, 2012.

Thread Status:
Not open for further replies.
  1. Feandur

    Feandur Registered Member

  2. The Red Moon

    The Red Moon Registered Member

    Thank you for this.:thumb:
    Not sure if im brave enough to try EMET.But it certainly looks interesting.
     
  3. Victek

    Victek Registered Member

  4. Aventador

    Aventador Registered Member

    The new versions runs a process and sits in the system tray. Better of with the previous version.
     
  5. Kees1958

    Kees1958 Registered Member

    Last edited: Sep 27, 2012
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    With the 3.0 version there were lots of reports of the new gui/systray process using a lot of resources, did they fix it in 3.5?
     
  7. 12000kb's in v3.5 in resources it takes up, not much if you ask me. Problem I see is if every man and his dog is installing it, it will be targeted and pulled apart.
     
  8. Robin A.

    Robin A. Registered Member

    About EMET: what is exactly the meaning of "Application Opt-In" (or “Application Opt-Out")?
     
  9. Victek

    Victek Registered Member

    "Opt-In" means the feature is NOT enabled for all applications, only those apps you manually turn it ON for.

    "Opt-Out" means the opposite, ie the feature is enabled for all applications except for those you manually turn it OFF for. Hope that's clear.
     
  10. Hungry Man

    Hungry Man Registered Member

    Robin A.

    Opt In is the weakest. An application must 'Opt In' to use teh protection.

    Opt Out is stronger. An application will use the protection unless it explicitly 'opts out'.

    Always On is the strongest. All applications are forced to use it.

    @Victek, I believe that's incorrect.
     
  11. Victek

    Victek Registered Member

    So with the "Opt Out" setting apps with the necessary smarts can choose to not enable specific protections, and "always On" would mean the protections are forced On - is that correct?
     
  12. Hungry Man

    Hungry Man Registered Member

    Yes, that's correct.

    An application has to 'tell' the operating system it doesn't want to use the protection. But if it's ambiguous/ the program doesn't say what it wants it will be forced to use the feature (in opt out mode).

    Always on doesn't care if it tries to opt out - it forces it.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Ah thanks, and I see what you mean, I think MS should redesign EMET's implementation to make it less vulnerable to targeted attacks.
     
  14. Dark Shadow

    Dark Shadow Registered Member

    Still running 3.0 on netbooks on maximum security setting with no problems at all.:thumb:
     
  15. Robin A.

    Robin A. Registered Member

    It´s more clear now, thanks.
     
  16. treehouse786

    treehouse786 Registered Member

    why is there no 'opt out' option for ASLR?
     
  17. Hungry Man

    Hungry Man Registered Member

    There is on Windows 8 I think. But it doesn't really make sense because no application opts out - it would basically be Always On. Whereas DEP has always had an Opt Out.

    They'd have to introduce the Opt Out more slowly and considering that the default policy for DEP is still Opt In I don't exepct it to happen to fast.
     
  18. treehouse786

    treehouse786 Registered Member

    thanks for clarifying HM
     
  19. focus

    focus Registered Member

    Does EMET need to connect out through the firewall? It has tried to and I have blocked it but am wondering if this affects its performance in any respect.
     
  20. treehouse786

    treehouse786 Registered Member

    just noticed that if you double click the tray icon then it shows a text box for a few seconds. does this mean that EMET will notify us when it detects/blocks suspicious activity?

    screenshot here http://i.imgur.com/IVkML.png
     
  21. Hungry Man

    Hungry Man Registered Member

    It may have checked for updates or something. But no, it shouldn't need to otherwise.
     
  22. focus

    focus Registered Member

    Good deal. Thanks HM.
     
  23. Victek

    Victek Registered Member

    Thanks for confirming. By the way, the new ROP options in 3.5 are unchecked by default. I wonder if there's a new database that configures these options for well known apps?
     
  24. Hungry Man

    Hungry Man Registered Member

  25. Dark Shadow

    Dark Shadow Registered Member

    Yes it suppose to notify through a popup when it blocks something.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice