Emsisoft Anti-Expolit Protection and App Container

Status
Not open for further replies.
H

hjlbx

Thread author
@Fabian Wosar

Does anyone here at MT know if Emsisoft's newly introduced anti-exploit protection also covers Apps ?

More specifically, does it protect Apps running within the Apps container ?

There is a good reason why I ask such a thing. It appears other anti-exploit solutions do not cover Apps running in the App container.

The case might be that since there are technical differences between Apps and portable executables, it might be unnecessary or technically not possible.

However, the technical side of it I really do not know.
 

cutting_edgetech

Level 3
Verified
Feb 14, 2013
113
Which other Anti-Exploits do not cover Apps Container? Are you talking about plugin-container which covers add-ons, and plugins? I'm pretty sure MalwareBytes AE does. Wish I could answer your question about Emsisoft. The last time I tried it they had not rolled out their exploit protection yet.
 

Attachments

  • MBAE.jpg
    MBAE.jpg
    77.9 KB · Views: 382
H

hjlbx

Thread author
Which other Anti-Exploits do not cover Apps Container? Are you talking about plugin-container which covers add-ons, and plugins? I'm pretty sure MalwareBytes AE does. Wish I could answer your question about Emsisoft. The last time I tried it they had not rolled out their exploit protection yet.

I am referring to Windows and Windows Store type Apps.

EMET, HMP.A and MBAE do not cover App container - unless I am missing something.

EMET - add Windows App - no EMET protection
HMP.A - cannot even add Windows App to protections
MBAE - cannot even add Windows App to protections (as far as I remember)
 
D

Deleted member 178

Thread author
HMP.A - cannot even add Windows App to protections

Wrong, you can add windows apps , you have to do it manually

1- open Apps
2- open HMPA mitigation tab > click running Applications
3- select the Apps.
 
H

hjlbx

Thread author
Wrong, you can add windows apps , you have to do it manually

1- open Apps
2- open HMPA mitigation tab > click running Applications
3- select the Apps.

Huh ?

I try adding Windows Apps - like Calculator, Video, etc.

HMP.A does not list them under Exploit Mitigation > Running Applications.
 
D

Deleted member 178

Thread author
Huh ?

I try adding Windows Apps - like Calculator, Video, etc.

HMP.A does not list them under Exploit Mitigation > Running Applications.

you have to add them manually via "running application" using media mitigation
 
H

hjlbx

Thread author
you have to add them manually via "running application" using media mitigation

Running Windows Apps do not show in HMP.A list of Running Applications; only portable executables installed outside the Windows App container will show in the list.

I have tried multiple times.
 
H

hjlbx

Thread author
There are no straight-forward answers that I can find on this one - and don't feel like spending hour, upon hour, searching various sites.
 
D

Deleted member 178

Thread author
Running Windows Apps do not show in HMP.A list of Running Applications; only portable executables installed outside the Windows App container will show in the list.

I have tried multiple times.


i think you didn't pay enough attention to my above post, OPEN the app first, THEN HMPA

Ek9tqVL.png


all my Windows Apps are protected
 
D

Deleted member 178

Thread author
something hamper your HMPA and block it to detect the Windows Apps; i guess it is CIS...

CIS is crap :D

look at mine

QHiDrJZ.png
 
H

hjlbx

Thread author
Everyone is missing point...

Calculator.exe is a 32-bit executable that runs outside the Windows App container - it is a portable executable. It's file path is C:\Windows\System32 and C:\Windows\SysWOW64.

Calculator App only runs inside the Windows App container - it is not a portable executable - it is JavaScript-based.

Calculator.exe is NOT the same as Calculator (Windows) App.

One cannot add any apps that run inside the App Container to HMP.A or MBAE. You can add them to EMET, but EMET will not protect them.

Capture.PNG
 
  • Like
Reactions: Online_Sword
D

Deleted member 178

Thread author
this ?

hvcYwux.png


if this one , it is protected

the calc.exe i have in System32 & syswow64 open the window app
 
  • Like
Reactions: Online_Sword
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top