EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. Quitch

    Quitch Registered Member

    "Regular Joe" is never going to run EMET. This is a power user tool, pure and simple. It might end up on a "Regular Joe" machine, but only because a power user installed it.
     
  2. Solarlynx

    Solarlynx Registered Member

    If they weren't necessary then MS won't develop them. They are so ugly so it's obvious they are designed to repel hesitating users. :)
     
  3. itman

    itman Registered Member

    Finally got this 4.0 version to run with Trusteer Rapport. Actually, at max. EMET 4.0 settings, Trusteer Rapport runs OK. Problem is it TR does not like the following:

    Virtual protect
    Load Library
    Create Process/File

    It will dump a bunch of entries in the TR log file under "Browser Process Alteration." I played with all the individual EMET settings for IE to no avail. Only thing I have found to stop all the above TR log entries fron being generated is to turn off(set to "Never") TR's browser process alteration setting.
     
  4. wat0114

    wat0114 Registered Member

    This latest EMET 4.0 blows, at least when it comes to governing Chrome on XP SP3 :mad:

    At default settings Chrome freezes when trying to launch it, and no real improvement when I disable most of the other mitigation options. I didn't get these issues with 2.x
     
  5. elapsed

    elapsed Registered Member

    Probably because 2.x had far less mitigations, the only thing I can suggest is keep disabling mitigations until it works.
     
  6. wat0114

    wat0114 Registered Member

    That might help, although I had even disabled every memory mitigation but Chrome still froze :( At least it's working fine with Chrome on my Win 7 machine, even with every mitigation option checked.
     
  7. kupo

    kupo Registered Member

    Same problem, but not with chrome, adding my game to EMET will crash it even if no mitigation is checked.
     
  8. wat0114

    wat0114 Registered Member

    Yeah, I just ended up removing chrome.exe from the list.
     
  9. elapsed

    elapsed Registered Member

    Why would you add a game? Games purposely opt out of these mitigations as it will reduce performance.
     
  10. Quitch

    Quitch Registered Member

    Not according to Microsoft

    http://msdn.microsoft.com/en-us/library/bb430720.aspx

    Do games opt out? I think they simply don't opt in because secure coding isn't a thing in game development circles.
     
  11. CrusherW9

    CrusherW9 Registered Member

    Be careful with this. I heard that if you add Steam Games like CSS or anything that makes use of VAC, you can get banned for it.
     
  12. kupo

    kupo Registered Member

    Yup, I removed it now. However, it seems that unchecking mitigations doesn't work in the latest version as to what I and wat0114 experience.
     
  13. elapsed

    elapsed Registered Member

    I'm not going to read that entire thing. If you have a point to bring up, quote it and leave the source. A search for "game" resulted in nothing.

    Yes, I'm sure games opt out of certain mitigations because it reduces performance. They also have 0 need for them.

    Yes I've said this before, you're taking a pointless risk by doing so.
     
  14. Quitch

    Quitch Registered Member

    Oh for goodness sake, search for "performance impact". Honestly, you're soap-boxing on a subject, providing nothing to support your case, then refusing to read the materials which relate to the damn subject you're professing knowledge of!
     
  15. ance

    ance formerly: fmon

    Does EMET reduce browser performance too? :doubt:
     
  16. Hungry Man

    Hungry Man Registered Member

    DEP and ASLR have (literally and virtually, respectively) no performance impact. Same with SEHOP. Most protections have virtually none, other than the Anti-ROP, which should have near minimal.
     
  17. itman

    itman Registered Member

    I am running it on max. protection settings with deep hooks enabled. Noticed no impact at all using IE9 on WIN 7 x64 SP1. My PC does have a lot of "horsepower" however.

    I am using the Popular Software app profile and only added stand-alone Flashplayer to it.

    My understanding is once you start adding WIN OS files, it will impact performance.
     
  18. wolfrun

    wolfrun Registered Member


    Since we have the experts here, a question concerning EMET 4; Should I add explorer.exe and svchost.exe to APPS. Some are saying yes and some say no. o_O Currently have DEP opt out, SEHOP opt out and ASLR opt in.
     
  19. Hungry Man

    Hungry Man Registered Member

    Yeah, I don't know why anyone would recommend against that unless there are specific issues. If you don't get crashes, I think you should use it.
     
  20. itman

    itman Registered Member

    I know in the EMET forum compatibilty section, MS recommended not to protect explorer.exe. As far as scvhost.exe, I have never seen a recommendation to protect it. Perhaps on XP. On WIN 7/8, it is pretty well protected by the OS.
     
    Last edited: Jun 24, 2013
  21. Quitch

    Quitch Registered Member

    Can you link to this? I can see user posts around it, but nothing from MS.
     
  22. cruelsister

    cruelsister Registered Member

    On Windows 7, Delphi, Cornficker, Smitfraud. and Alureon variants have no issues circumventing any svchost protection.
     
  23. elapsed

    elapsed Registered Member

    My "soap-boxing", uhm, okay. I apologize that you didn't place enough detail in your response to me, clearly, this is my fault for your incapability to form a response.

    No where in that article does it mention games, whatsoever. No where does it recommend having games opt into these mitigations.

    This is what you said:
    Which was a direct response to my post about games, and also an entirely flawed one as the link you provided does not mention games.

    Nearly half of the mitigations listed have negligible-to-possible performance loss. Whilst this means nothing for your every day application such as a browser, it has the potential to mean a lot for games where you're trying to cram out every possible frame. It's up to the developers to measure said performance and ask themselves what's the point in even opting in.
     
  24. wolfrun

    wolfrun Registered Member

    Thanks for the responses from you and Quitch. Well, I had added explorer.exe and svchost.exe to APPS for the past week and so far no problems or crashes. I really wanted to know yours and others opinion on it.
     
  25. 1chaoticadult

    1chaoticadult Registered Member

    I have had explorer and svchost added since EMET 3 and I have not any issues.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice