Enhanced Mitigation Experience Toolkit (EMET)

   Information
The Enhanced Mitigation Experience Toolkit(EMET) is a utility that helps prevent vulnerabilities in software from being successfully exploited. EMET achieves this goal by using security mitigation technologies. These technologies function as special protections and obstacles that an exploit author must defeat to exploit software vulnerabilities. These security mitigation technologies do not guarantee that vulnerabilities cannot be exploited. However, they work to make exploitation as difficult as possible to perform.

EMET 4.0 and newer versions also provide a configurable SSL/TLS certificate pinning feature that is called Certificate Trust. This feature is intended to detect man-in-the-middle attacks that are leveraging the public key infrastructure (PKI).

Software vulnerabilities and exploits have become an everyday part of life. Virtually every product has to deal with them and consequently, users are faced with a stream of security updates. For users who get attacked before the latest updates have been applied or who get attacked before an update is even available, the results can be devastating: malware, loss of PII, etc.

Security mitigation technologies are designed to make it more difficult for an attacker to exploit vulnerabilities in a given piece of software. EMET allows users to manage these technologies on their system and provides several unique benefits:

1. No source code needed: Until now, several of the available mitigations (such as Data Execution Prevention) have required for an application to be manually opted in and recompiled. EMET changes this by allowing a user to opt in applications without recompilation. This is especially handy for deploying mitigations on software that was written before the mitigations were available and when source code is not available.

2. Highly configurable: EMET provides a higher degree of granularity by allowing mitigations to be individually applied on a per process basis. There is no need to enable an entire product or suite of applications. This is helpful in situations where a process is not compatible with a particular mitigation technology. When that happens, a user can simply turn that mitigation off for that process.

3. Helps harden legacy applications: It’s not uncommon to have a hard dependency on old legacy software that cannot easily be rewritten and needs to be phased out slowly. Unfortunately, this can easily pose a security risk as legacy software is notorious for having security vulnerabilities. While the real solution to this is migrating away from the legacy software, EMET can help manage the risk while this is occurring by making it harder to hackers to exploit vulnerabilities in the legacy software.

4. Ease of use: The policy for system wide mitigations can be seen and configured with EMET's graphical user interface. There is no need to locate up and decipher registry keys or run platform dependent utilities. With EMET you can adjust setting with a single consistent interface regardless of the underlying platform.

5. Ease of deploy: EMET comes with built-in support for enterprise deployment and configuration technologies. This enables administrators to use Group Policy or System Center Configuration Manager to deploy, configure and monitor EMET installations across the enterprise environment.

6. Ongoing improvement: EMET is a living tool designed to be updated as new mitigation technologies become available. This provides a chance for users to try out and benefit from cutting edge mitigations. The release cycle for EMET is also not tied to any product. EMET updates can be made dynamically as soon as new mitigations are ready

The toolkit includes several pseudo mitigation technologies aimed at disrupting current exploit techniques. These pseudo mitigations are not robust enough to stop future exploit techniques, but can help prevent users from being compromised by many of the exploits currently in use. The mitigations are also designed so that they can be easily updated as attackers start using new exploit techniques.


For more information about EMET, see:
   Note
If you install EMET and do not "Configure System" settings, it doesn't do anything to the Windows Data Execution Prevention (DEP) settings.

If you install EMET and "Configure System" settings to Recommended, it will change the DEP to Turn on for essential Windows programs and services only, if you already have it set to everything.

If you install EMET and "Configure System" settings to Maximum, it will gray out the default DEP settings since EMET will be used instead.

DEP.jpg
   Warning
Updated Support End Date for EMET 5.5x

Finally, we have listened to customers’ feedback regarding the January 27, 2017 end of life date for EMET and we are pleased to announce that the end of life date is being extended 18 months. The new end of life date is July 31, 2018. There are no plans to offer support or security patching for EMET after July 31, 2018. For improved security, our recommendation is for customers to migrate to Windows 10.

See: Windows: Moving Beyond Enhanced Mitigation Experience Toolkit (EMET)




Enhanced Mitigation Experience Toolkit (EMET) 5.5.2

Release date: November 14th 2016
Supported Client Operating Systems: Windows 10 , Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 SP1, Windows Server 2008 Service Pack 2, Windows Server 2012, Windows Server 2012 R2, Windows Vista Service Pack 2

- EMET 5.52 requires .NET Framework 4.5.
- For Internet Explorer 10 on Windows 8 you need to install KB2790907 – a mandatory Application Compatibility update that has been released on March 12th, 2013 or any other Application Compatibility updates for Windows 8 after that.

User Guide: User Guide for EMET 5.52



Download




EMET_4.0_setup-1.jpg

EMET_4.0.jpg



 
Last edited:
Thank you Loki. Tutorial updated. :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
EMET 5.0 has some major changes and was not as easy as previous versions to configure. Many apps crashed. I spent a lot of time testing and reading about problems with it. Here's what's good to know:


  • The setting Deep Hooks under Configuration of Apps, has due to compatibility issues always been disabled by default in previous EMET versions. Now it's on by default, but that doesn't mean it'll work on every system
  • EAF isn't compatible with some programs
  • Crashes that don't give alerts from EMET might be caused by the mitigation StackPivot. It's been modified in 5.0, so it might not be compatible for some programs anymore
  • New mitigation ASR blocks certain plug-ins from being loaded, sometimes with exceptions from defined Internet Zones (Trusted Sites, Local Intranet)
  • New mitigation EAF+ blocks some memory read operations commonly used as information leaks
ASR and EAF+ are advanced settings that come predefined for some MS applications when importing settings for the Recommended Software or Popular Software list. There's a bug that if you disable and re-enable any of these two new mitigations, the settings for it is deleted.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Is EMET 4.1 still considered good enough?

With 4.1 I found the ROP protections crash firefox randomly. Also the game 'godus' had issues with EMET and I had to whitelist it (no idea if dev's ever made it compatible as is a game still in development). Apart from that tho seems fine with all my other apps.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers
Hello Chrysalis,

It would be recommended to update to the latest EMET 5.0 version. You can install it on top of any previous version to update.

I only left EMET 4.1 Update 1 listed since it's the last version that officially supports XP.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
EMET 5.1 released. See first post for more details. :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
I've been testing 5.1 and I like it. I can enable more mitigations than in 5.0, mostly StackPivot.

Good to know:
I had lots of problems with 5.0 and I've now learned that EMET itself is not necessarily the reason for these problems(crashes). It's very likely that another security product is causing conflicts. In my case it was the HIPS functionality in my AV software. With that disabled, or at least the dll injection/monitoring part of the HIPS, I wouldn't have had to disable ANY mitigation for the "Popular Software" import XML file in EMET 5.1
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Latest Patch Tuesday(Windows Updates - November) might cause incompatibility issues with EMET 5.0

If you are using Internet Explorer 11, either on Windows 7 or Windows 8.1, and have deployed EMET 5.0, it is particularly important to install EMET 5.1 as compatibility issues were discovered with the November Internet Explorer security update and the EAF+ mitigation. Alternatively, you can temporarily disable EAF+ on EMET 5.0. Details on how to disable the EAF+ mitigation are available in the User Guide. In general we recommend upgrading to the latest version of EMET to benefit from all the enhancements.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Does anyone have a app list for emet 5.1 and what to exclude firefox etc? I am on still on 4.1 but I guess thats getting dated now security wise.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers
App List for EMET

Does anyone have a app list for emet 5.1 and what to exclude firefox etc? I am on still on 4.1 but I guess thats getting dated now security wise.

As far as I know you just open the EMET GUI and choose "Import" and then select the .xml file that you want to import. Right click on each .xml file and open with your text editor to see what's in it.

I really don't think that you should exclude Firefox or any other browser.

Just add any of the following:

* Any/all web browsers installed on your computer (Internet Explorer, Firefox, Chrome, Opera)
* Entire MS Office suite (Access, Excel, Outlook, PowerPoint, Word)
* Sun (now Oracle) Java
* Any media player (Windows Media Player, VLC, iTunes, RealPlayer, QuickTime, Winamp)
* Any software that waits and listens for a network connection
* Any application that can be automatically invoked by browsing the internet
* Any Adobe product that you see frequently listed within Adobe's Security bulletins and advisories.

You will need to know what software you have installed and what to add. There's no all inclusive list of all available software and anyway you only want to load it with apps that you actually use.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
In addition to Callender's post:

If you meant what EMET mitigations to exclude for a specific program, then that's adjusted in the xml import files for every new EMET release. So when you import a program list these programs should work with the default settings/mitigations. If they don't it's likely that you have some other security software installed that conflicts with EMET, for example an antivirus, HIPS, or another exploit blocker.

If you have to disable a lot of mitigations in the new EMET version and you can't troubleshoot it, it's probably better and easier to go back to EMET 4.1 if you could have more mitigations enabled there.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
I mentioned firefox as on other forums like wilders people are mentioning a lot having to disable certian protections for firefox and chrome. I dont mean to exclude the app entirely, and on 4.1 I also had to turn of some ROP for firefox as it kept crashing with it on, I dont have HIPS on any a/v so isnt any conflict.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers
What AV do you have? Some have their own exploit/behavior blocker that might conflict
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
eset nod32 a/v not the full nod32.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
Two users in the EMET thread at Wilderssecurity have posted their experience about potential conflicts with EMET:

Just as a potential FYI, here's a list of AVs which have any kind of behavior-based anti-exploit I'm currently aware of, so potentially more possibility of conflicts though not always the case.

ESET ver 7+
F-secure (all products which have DeepGurad 6.0+)
G-Data (don't know which version)
KIS 2013+
Norton 2010+
Pand Cloud v2.2+
My observations.

ESET NOD32 - seems to work fine with EMET 5.0.
F-Secure AV - default Deepguard settings cause major issues with EMET 5.0
Solution:
Deepguard - select 'Use the Compatibility Mode'. Note - they say it lowers security. OTH you're using EMET.
In EMET 5.0 EAF+ is OK in Firefox but delete advanced rules [eg: mozjs.dll;xul.dll] otherwise Firefox start-ups are very slow.
Otherwise select all mitigations in Firefox except ASR, as recommended by MS.
Post 765: EMET (Enhanced Mitigation Experience Toolkit) | Page 31 | Wilders Security Forums
and post 768

For F-Secure an alternative solution for using the compatibility mode is to exclude only the programs that conflict with EMET in settings - Virus protection - Exclude files from the scan - tab Objects. This will exclude the programs from the real-time scan which also means Deepguard won't hook into these processes. For known programs that's the preferred solution until the conflict between EMET and Deepguard has been resolved.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
New Enhanced Mitigation Experience Toolkit (EMET) 5.2 released. See first post for more details. :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
Thank you David. Tutorial updated. :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
New Enhanced Mitigation Experience Toolkit (EMET) 5.5 released. See first post for more details. :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Back
Top