EMET - a dummy's guide

Discussion in 'other anti-malware software' started by Feandur, Sep 26, 2012.

Thread Status:
Not open for further replies.
  1. Feandur

    Feandur Registered Member

    Joined:
    Jun 15, 2005
    Posts:
    429
    Location:
    Australia
  2. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,101
    Thank you for this.:thumb:
    Not sure if im brave enough to try EMET.But it certainly looks interesting.
     
  3. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
  4. Aventador

    Aventador Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    420
    The new versions runs a process and sits in the system tray. Better of with the previous version.
     
  5. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Last edited: Sep 27, 2012
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    With the 3.0 version there were lots of reports of the new gui/systray process using a lot of resources, did they fix it in 3.5?
     
  7. 12000kb's in v3.5 in resources it takes up, not much if you ask me. Problem I see is if every man and his dog is installing it, it will be targeted and pulled apart.
     
  8. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,557
    About EMET: what is exactly the meaning of "Application Opt-In" (or “Application Opt-Out")?
     
  9. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    "Opt-In" means the feature is NOT enabled for all applications, only those apps you manually turn it ON for.

    "Opt-Out" means the opposite, ie the feature is enabled for all applications except for those you manually turn it OFF for. Hope that's clear.
     
  10. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Robin A.

    Opt In is the weakest. An application must 'Opt In' to use teh protection.

    Opt Out is stronger. An application will use the protection unless it explicitly 'opts out'.

    Always On is the strongest. All applications are forced to use it.

    @Victek, I believe that's incorrect.
     
  11. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    So with the "Opt Out" setting apps with the necessary smarts can choose to not enable specific protections, and "always On" would mean the protections are forced On - is that correct?
     
  12. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Yes, that's correct.

    An application has to 'tell' the operating system it doesn't want to use the protection. But if it's ambiguous/ the program doesn't say what it wants it will be forced to use the feature (in opt out mode).

    Always on doesn't care if it tries to opt out - it forces it.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Ah thanks, and I see what you mean, I think MS should redesign EMET's implementation to make it less vulnerable to targeted attacks.
     
  14. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Still running 3.0 on netbooks on maximum security setting with no problems at all.:thumb:
     
  15. Robin A.

    Robin A. Registered Member

    Joined:
    Feb 25, 2006
    Posts:
    2,557
    It´s more clear now, thanks.
     
  16. treehouse786

    treehouse786 Registered Member

    Joined:
    Jun 6, 2010
    Posts:
    1,411
    Location:
    Lancashire
    why is there no 'opt out' option for ASLR?
     
  17. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    There is on Windows 8 I think. But it doesn't really make sense because no application opts out - it would basically be Always On. Whereas DEP has always had an Opt Out.

    They'd have to introduce the Opt Out more slowly and considering that the default policy for DEP is still Opt In I don't exepct it to happen to fast.
     
  18. treehouse786

    treehouse786 Registered Member

    Joined:
    Jun 6, 2010
    Posts:
    1,411
    Location:
    Lancashire
    thanks for clarifying HM
     
  19. focus

    focus Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    503
    Location:
    USA
    Does EMET need to connect out through the firewall? It has tried to and I have blocked it but am wondering if this affects its performance in any respect.
     
  20. treehouse786

    treehouse786 Registered Member

    Joined:
    Jun 6, 2010
    Posts:
    1,411
    Location:
    Lancashire
    just noticed that if you double click the tray icon then it shows a text box for a few seconds. does this mean that EMET will notify us when it detects/blocks suspicious activity?

    screenshot here http://i.imgur.com/IVkML.png
     
  21. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It may have checked for updates or something. But no, it shouldn't need to otherwise.
     
  22. focus

    focus Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    503
    Location:
    USA
    Good deal. Thanks HM.
     
  23. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Thanks for confirming. By the way, the new ROP options in 3.5 are unchecked by default. I wonder if there's a new database that configures these options for well known apps?
     
  24. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
  25. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Yes it suppose to notify through a popup when it blocks something.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.