Category: System ToolsSoftware version: 5.52.6156.38091
Language: English
Treatment: not required
System requirements:
Windows 10 (versions 1507, 1511 and 1607), Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 Service Pack 2, Windows Server 2012, Windows Server 2012 R2, Windows Vista Service Pack 2 , Windows 8;
- To use EMET, you need the Microsoft .NET Framework 4.5. In addition, to work EMET with Internet Explorer 10 in Windows 8 and Windows Server 2012, you must have the compatibility update KB2790907, released on March 12, 2013, or a newer version for Windows 8 or Windows Server 2012.
Description:
The EMET toolkit is a utility that prevents the exploitation of vulnerabilities in the software. This is achieved through the use of risk reduction technologies. These technologies are special protection tools and obstacles that the exploit developer must bypass to take advantage of vulnerabilities in the software. The use of risk mitigation technologies does not guarantee that attackers will not be able to exploit vulnerabilities, but complicates the achievement of this goal as much as possible.
The Enhanced Mitigation Experience Toolkit (EMET) works in conjunction with Microsoft solutions or third-party anti-virus vendors to enhance protection from attacks that target popular and common software: Internet Explorer, Office, Acrobat, and Java.
EMET also provides a customizable SSL / TLS binding function, called "Certificate Trust". This function is designed to detect (and stop using EMET 5) an "intruder in the middle" attacks that use a public key infrastructure (PKI).
The easiest way to deploy the current version of EMET to your organization is through enterprise deployment and configuration technologies. The current version has built-in support for Group Policy and System Center Configuration Manager.
Additional Information:
The Enhanced Mitigation Experience Toolkit (EMET) is designed to help clients develop a deep defense strategy against cyberattacks, helping to identify and block exploitable practices that are commonly used to exploit memory-related vulnerabilities. Enhanced Mitigation Experience Toolkit (EMET) helps to raise the bar against cybercriminals trying to access computer systems. EMET anticipates the most common actions and methods that opponents can use to compromise a computer, and helps protect, distract, complete, block and annul these actions and methods. EMET helps protect your computer systems even before new and undiscovered threats are officially eliminated through security updates and malware protection software. EMET benefits businesses and all computer users by helping to protect against security threats and security breaches that can disrupt business and disrupt everyday life.
Enhanced Mitigation Experience Toolkit (EMET) allows you to cope with perhaps the most important problem for Windows users - protection from zero-day attacks.
Zero-day attacks are the latest threats, which due to their small age are unknown to the antivirus software installed in the system.
EMET is a free standalone security application, but is not positioned as a universal anti-virus solution. The component works in conjunction with Microsoft solutions or third-party anti-virus software vendors to enhance protection from attacks that target popular and common software: Internet Explorer, Office, Acrobat, and Java. EMET is compatible with all current versions of Windows, from Vista SP2 and Windows Server 2003 SP2 to Windows 10 and Windows Server 2012 R2.
The product is perfectly prepared for the corporate environment, but according to Microsoft, the tool can also be used to protect home computers.
If you are confronted with the tasks that are associated with confidential personal information - orders or Internet banking - installation of EMET 5 is highly recommended.
The main features of Microsoft EMET:
Data Execution Prevention (DEP) is a security feature that protects even those applications whose architecture was not originally prepared for EMET. The product significantly extends the system protection of DEP. DEP technology helps prevent attacks that store code in the memory area by buffer overflow. EMET reserves certain areas of computer memory for the corresponding types of programs. For example, the memory reserved for executable files will only be used for programs, services, and device drivers. In this case, the cyber criminals can not use these memory zones to hide malicious code.
Structured Exception Handler Overwrite Protection (SEHOP), a technology first introduced in 2009, helps prevent attacks that overwrite the exception handler - in other words, the exploit of "buffer overflow".
Address Space Layout Randomization (ASLR) - randomly changes the location in the address space of key application components, making it difficult for a hacker to access known vulnerabilities in the application code. Without ASLR, the application runs in special areas of the memory address space. ASLR is supported by Windows Vista and all subsequent Windows operating systems.
Certificate Trust (Pinning): We still rely heavily on security certificates as a preventive measure of protection on the network. By default, EMET believes that some secure Socket Layer certificates are trusted. The product also believes that the sites Facebook, Skype, Twitter, Yahoo and Microsoft have reliable certificates. Sites whose certificates do not meet EMET expectations are automatically blocked. This feature can help out, for example, when a user attempts to visit a fake Facebook site.
Helps raise the bar against intruders. EMET helps protect against new and undetected threats even before they are officially resolved with security updates or malware protection software. EMET includes 14 security measures that complement other similar security measures, such as Windows Defender and anti-virus software. EMETs are installed with default security profiles, which are XML files that contain preconfigured settings for common Microsoft and third-party applications.
Works well in enterprises. Corporate IT professionals can easily deploy EMET using the Microsoft System Center Configuration Manager and apply group policies in Windows Active Directory to match the policies of the corporate user account and the enterprise role. Administrators can customize and individualize EMET by deploying it and determining which applications they want to protect using mitigation methods.
Even for legacy enterprise software that can not be easily overwritten, or for software when the source code is not available, EMET provides protection. The reporting capabilities in EMET are provided through a component called the EMET Agent, which allows enterprises to create logs and notifications for audit purposes. EMET Customer Support is available through Microsoft Premier Support Services. For more information about EMET deployment, please visit the EMET Knowledge Base article: KB2458544.
Provides protection in a wide range of scenarios. EMET is compatible with the most commonly used third-party applications at home and in the enterprise, from software to increase productivity to music players. EMET works in the range of client and server operating systems used at home and in the enterprise. When users view protected HTTPS sites on the Internet or when entering popular social networks, EMET can help in further protection by verifying Secure Sockets Layer (SSL) certificates for compliance with user rules.
Security settings EMET:
• Attack Surface Reduction (ASR)
• Export Address Table Filtering (EAF +)
• Data Execution Prevention (DEP)
• Structured Execution Handling Overwrite Protection (SEHOP)
• NullPage
• Heapspray Allocation
• Export Address Table Filtering (EAF)
• Obligatory Address Space Layout Randomization (ASLR)
• Bottom Up ASLR
• Download library checkout - Return Oriented Programming (ROP)
• Memory protection check - Return Oriented Programming (ROP)
• Call verification - Return Oriented Programming (ROP)
• Simulation of the executed flow - Return Oriented Programming (ROP)
• The return point of the stack is Return Oriented Programming (ROP)
• Untrusted Windows fonts 10
New features and updates:
• Compatible with Windows 10;
• Improved configuration of various patches with the help of Group Policy;
• Full GPO support for preventing effects and added the ability to secure certificates;
• Increased productivity in EAF / EAF + area;
• Prevent installation of untrusted fonts for Windows 10;
• The problem of reducing EAF, which causes some applications to hang in Windows 7 with Service Pack 1 (SP1);
• Repair MSI installer, which allows you to perform an in-place upgrade;
• Eliminate the consequences for Chrome from Popular Software.xml;
• Fixed import behavior for system protection;
• Numerous bug fixes.
To extract files from the archive, please download and install the RARArchiver software.
Download: Microsoft Enhanced Mitigation Experience Toolkit (EMET) 5.52.6156.38091 [En] SIZE: 25.5MB
0 comments: