4 ms·
You can control almost all EMET mitigations except for the ROP and EAF protections through IFEO (Image File Executable Options). There's also the cert pinning
by ryuuchin 10y ago
You can control almost all EMET mitigations except for the ROP and EAF protections through IFEO (Image File Executable Options). There's also the cert pinning but I believe that was only useful for IE. There are also other Windows 10 specific mitigations that don't exist in EMET which can also be controlled this way. The main selling point of EMET was that it did not require recompilation. Luckily you can still control most of these mitigations through IFEO (see below) which does not require recompilation.
EAF uses debug registers which limits its usefulness and the ROP mitigations are becoming less useful because of CFG (control flow guard). Although the latter does require applications to be recompiled with the latest Visual Studio (and Opt-In to using CFG which is not enabled by default). It's not really surprising seeing Microsoft retire EMET considering you can get nearly the same kind of coverage on a vanilla Windows 10 install.
I made a rough guide as to the layout of the MitigationOptions QWORD which controls these mitigations:
https://theryuu.github.io/ifeo-mitigationoptions.txt https://theryuu.github.io/ifeo-mitigationoptions.txt
There are Microsoft provided functions which can also enable these mitigations[1][2] when compiled into the code. Also lets not forget that for now EMET still works fine with Windows 10.
[1] https://msdn.microsoft.com/en-us/library/windows/desktop/ms686880%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/ms6...
[2] https://msdn.microsoft.com/en-us/library/windows/desktop/hh769088%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/hh7...