Blog

Sorting upcoming challenges.... (11 days ago)

Enhanced Mitigation Evaluation Toolkit – A toolkit to apply security mitigation technologies to arbitrary applications

has released a new for hardening binary applications without the need of recompilation. It is called Evaluation – A to apply security technologies to applications. Direct Link here. Maybe someone has time to check this tool?

Cited from website:

Security technologies are technologies designed to make it more difficult for an attacker to exploit vulnerabilities in a given piece of software. The Enhanced Evaluation () is a that allows certain security technologies to be applied to user specified applications. It provides four unique capabilities:

1. Until now, many of the available mitigations have required for an application to be manually opted in and recompiled. changes this by allowing a user to opt in applications via a simple command-line utility without recompilation. This is especially handy for deploying mitigations on software that was written before the mitigations were available and when source code is not available.

2. provides a higher degree of granularity by allowing mitigations to be applied on a per process basis. There is no need to enable an entire product or suite of applications. This is helpful in situations where a process is not compatible with a particular technology. When that happens, a user can simply turn off for that process.

3. Mitigations that have previously been limited to up-level versions of Windows now ship with and are available down-level. Users can benefit from these mitigations without the need to upgrade their systems.

4. is a living tool designed to be updated as new technologies become available. This provides a chance for users to try out and benefit from mitigations before they are included in the next versions of our products. It also gives users the opportunity to provide feedback and help guide the future of technologies in products.

Dr. Thorsten Schneider - I am the Lecturer of the Technical Faculty, Bielefeld University. My teaching is programming languages, software engineering, software development methodologies, project management, process management, binary auditing, IT security & ethical hacking.

Leave a Reply