pallino Posted July 22, 2015 Report Share Posted July 22, 2015 Hello Emsi Team, does Emsi offer a anti exploit protection? For e.g, did/does Emsi protect from APT3’s hp.swf CVE -2015-3113 exploit code? https://www.virustotal.com/en/file/ff3163c628649a13c765d7abfa933223bf45374830e3052fbf52c0bf4bcaf5a1/analysis/1435248343/ thank you! Link to comment Share on other sites More sharing options...
Fabian Wosar Posted July 22, 2015 Report Share Posted July 22, 2015 That is the same question as the file-less infection one. No, we do not provide anti-exploit capabilities. We do protect from the payload these exploits drop, but we do not attempt to mitigate the exploit itself. Link to comment Share on other sites More sharing options...
pallino Posted July 22, 2015 Author Report Share Posted July 22, 2015 ...similar since it was specific about file-less infections. I hoped BB would protect somehow from exploits. Are you thinking at adding some anti-exploit features in the future (alone or, maybe through acquisition/merge with others? :-) )? Link to comment Share on other sites More sharing options...
Fabian Wosar Posted July 22, 2015 Report Share Posted July 22, 2015 The problem is that a significant portion of our users expect EAM to run alongside other AVs, which often already implement exploit mitigation features. Multiple exploit mitigations will ultimately clash in many cases. If you ever tried to run MBAE alongside EMET you know what I am talking about. So we will do it only if we can somehow maintain compatibility with other AVs. Link to comment Share on other sites More sharing options...
pallino Posted July 23, 2015 Author Report Share Posted July 23, 2015 Why should someone need/want to use Emsi with other AV? The day Emsi will have a anti-exploit users will have no reason to install other solutions....and if this will not allow to run Emsi alongside other AV, probably, even better...or? :-) Link to comment Share on other sites More sharing options...
Sintharius Posted July 23, 2015 Report Share Posted July 23, 2015 Some people use EAM for its antimalware capabilities to support other AVs with poor AM detection (i.e. Kaspersky). So compability is important IMO. Link to comment Share on other sites More sharing options...
Peter2150 Posted July 23, 2015 Report Share Posted July 23, 2015 Why should someone need/want to use Emsi with other AV? The day Emsi will have a anti-exploit users will have no reason to install other solutions....and if this will not allow to run Emsi alongside other AV, probably, even better...or? :-) You keep asking the same question and getting the same answer. I would suggest putting it to rest and relax. You are protected. Link to comment Share on other sites More sharing options...
pallino Posted July 23, 2015 Author Report Share Posted July 23, 2015 I don t want to start a discussion about this but I don't agree if I didn't ask, I and others wouldn't know that Emai does not detect filess infections at all in realtime, that an anti-exploit is a must, that Emsi is used by many to add security to ather AV...etc...only with curiosity and questions/good answers you learn and improve. :-) Now I rest and relax. :-) Link to comment Share on other sites More sharing options...
Fabian Wosar Posted July 23, 2015 Report Share Posted July 23, 2015 Actually, nothing of this is new and has been discussed repeatedly here and in other communities as well. Link to comment Share on other sites More sharing options...
pallino Posted July 23, 2015 Author Report Share Posted July 23, 2015 Of course, I m sure all this is all easily and quicly available on the internet. I lost a lot of time to find this out, e.g on Wilders where there is a long discussion about if filess infectiond are detected or not by some products...I saw many many people confused or with wrong ideas. I doubt many people knew and know that Emsi as other programs cannot, as you said, as of now detect in realtime filess infections. Anyway I know more now, I'm happy and safer and happy to think I could help other people to find many clear answers only on one page.. thanks Link to comment Share on other sites More sharing options...
Fabian Wosar Posted July 27, 2015 Report Share Posted July 27, 2015 If you have any further questions, feel free to ask. Link to comment Share on other sites More sharing options...
pallino Posted July 28, 2015 Author Report Share Posted July 28, 2015 Thank you Link to comment Share on other sites More sharing options...
Fabian Wosar Posted July 30, 2015 Report Share Posted July 30, 2015 You are welcome. Link to comment Share on other sites More sharing options...
Recommended Posts