Avatar of sunhux
sunhux
 asked on

EMET deprecated but CIS Win 2019 benchmark still recommends enabling it

CIS hardening benchmarks for Win 2016 (pg 534) & 2019 (pg 463 & 690)
 both indicated to enable EMET : attached.

However, link below indicates it's been EOL so does it
still make sense to install/enable EMET or there's a newer
version of EMET?

https://support.microsoft.com/en-sg/help/2458544/the-enhanced-mitigation-experience-toolkit 

Is ASLR & DEP also deprecated  as well?
CIS_Microsoft_Windows_Server_2016_RT.pdf
CIS_Microsoft_Windows_Server_2019_RT.pdf
Windows OSSecurity

Avatar of undefined
Last Comment
btan

8/22/2022 - Mon
SOLUTION
David Johnson, CD

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
sunhux

ASKER
Is EMET coded directly into Win2019 & how can I show auditors this?
Any settings in Win2019 or MS has articles for this?

We have Win2019 AD/DC servers.
SOLUTION
btan

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
sunhux

ASKER
> what is your hardening baseline
In our case, 2 teams of Ernst Young auditors practise
differently: one audit based on our organization's baseline
doc while the other team persisted on using CIS as the
2nd team felt we 'simplified' our baseline (so that we have
less  settings to comply to).

So to opt for something deterministic, we install EMET?

So to say, we should still adopt CIS Win 2019's benchmark
of enabling EMET, DEP, SEHOP, ASLR and for crown jewel
like AD/DC, go for the 'high' settings that BTan suggested?

For low-criticality servers, opt for the 'low' settings?
ASKER CERTIFIED SOLUTION
btan

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes