280 likes | 426 Views
Sheep & Sheepdogs. Employing EMET for Application Security. About Me. GCIA, GCIH, GSEC, CCNA, CISSP dcoursey@rootsec.net @ dacoursey. Microsoft. Enhanced Mitigation Experience Toolkit (EMET). The Dawn of Time. Sheep. MS Office Acrobat Flash Java. Fences. DEP ASLR SEHOP
E N D
Sheep & Sheepdogs Employing EMET for Application Security
About Me GCIA, GCIH, GSEC, CCNA, CISSP dcoursey@rootsec.net @dacoursey
Microsoft Enhanced Mitigation Experience Toolkit (EMET)
Sheep • MS Office • Acrobat • Flash • Java
Fences • DEP • ASLR • SEHOP • etc…
Security Development Lifecycle Progress Report ASLR DEP
EMET What is it?
Enterprise But what about…
The Bad News What does it NOT do?
Enterprise Deployment
Enterprise Management
Enterprise Microsoft’s Strategy
References http://blogs.technet.com/b/srd/archive/2010/12/08/on-the-effectiveness-of-dep-and-aslr.aspx?Redirected=true https://blogs.technet.com/b/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx?Redirected=true https://blogs.technet.com/b/security/archive/2012/08/08/microsoft-s-free-security-tools-enhanced-mitigation-experience-toolkit.aspx?Redirected=true http://technet.microsoft.com/en-us/library/dd837644(v=ws.10).aspx