# Securing your Microsoft Machine

**URL:** <https://forums.speedlife.net/t/securing-your-microsoft-machine/62335>\
**Category:** NYSpeed Off Topic\
**Created:** [February 2, 2009, 2:44pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335 "2009-02-02T14:44:36Z")\
**Posts on this page:** 20\
**Page:** 7

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [May 16, 2013, 6:37am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/121 "2013-05-16T06:37:07Z")

</div>

I use firefox mainly. Chrome on the laptop at home (because wifey uses firefox and the machine is dog slow with multiple accounts).

I was just finding that Chrome was buggy on linux, I hate that I cannot set it up to run in Incognito mode by default, and I was pretty sure that there was some bug that was causing my iMac to randomly reboot.

Firefox is rock solid on all platforms. I’ll live with the small percentage of increased security risk.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [June 17, 2013, 5:04pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/122 "2013-06-17T17:04:32Z")

</div>

EMET 4.0 has been released

[http://www.microsoft.com/en-us/download/details.aspx?id=39273](http://www.microsoft.com/en-us/download/details.aspx?id=39273)

You should probably install this :tup:

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 17, 2013, 5:53pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/123 "2013-06-17T17:53:39Z")

</div>

IN your experience are corporations rolling this out to their PCs?

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [June 17, 2013, 6:24pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/124 "2013-06-17T18:24:37Z")

</div>

> [@ProgRocker](#):
>
> IN your experience are corporations rolling this out to their PCs?

I have

> **[Archived MSDN and TechNet Blogs](https://learn.microsoft.com/en-us/archive/blogs/)**

Some info on enterprise deployment there.

Basically this helps mitigate exploits getting code execution even when anti virus doesn’t detect whatever payload it might try and execute or whatever application doesn’t have the patch fixing some 0day

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 17, 2013, 6:30pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/125 "2013-06-17T18:30:23Z")

</div>

Yep, deployment through SCCM would be a breeze with this especially with an MSI file. I’d need to push out .Net Framework 4 for machines though.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [June 18, 2013, 2:05pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/126 "2013-06-18T14:05:46Z")

</div>

Don’t really see any issues you would deploy it then enabled it for a select list of applications…

If you ever ran into an issue just disable it on whatever application…

But I would opt in all browsers, java, adobe, and whatever else might open internet content.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 18, 2013, 2:30pm UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/127 "2013-06-18T14:30:09Z")

</div>

apparently there is ADMX templates too…can’t find em though.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 28, 2013, 7:18am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/128 "2013-06-28T07:18:29Z")

</div>

Ok found the ADMX files, greated a GPO for them. Now creating an SCCM package for deployment and then I’m going to start testing some stuff.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [June 28, 2013, 7:23am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/129 "2013-06-28T07:23:32Z")

</div>

We have been doing standard image audits for customers and writing hardening guides we now include EMET as a recommendation for all customers.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 28, 2013, 7:36am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/130 "2013-06-28T07:36:46Z")

</div>

> [@LZ](#):
>
> We have been doing standard image audits for customers and writing hardening guides we now include EMET as a recommendation for all customers.

I still don’t QUITE know how to explain it in laymans terms to people on what it actually does.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [June 28, 2013, 7:46am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/131 "2013-06-28T07:46:45Z")

</div>

I usually just explain that there are 0day bugs and exploits in the wild that can compromise systems and often times the bugs are taken advantage of on the internet before there is ever a patch.

EMET helps stop these threats before the vendors can release a patch

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [June 28, 2013, 8:04am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/132 "2013-06-28T08:04:59Z")

</div>

Definitely pitching this as a mitigation tool and to be added to standard images. Might help some of the risk with running apps that require out-of-date runtimes.

---

<div class="post-metadata">

**Author:** ![ProgRocker](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/progrocker/32/5434_2.png) [@ProgRocker](https://forums.speedlife.net/u/ProgRocker)\
**Post date:** [June 28, 2013, 9:02am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/133 "2013-06-28T09:02:14Z")

</div>

Deployed to two machines so far and both claim the the EMET client isn’t running when you open the GUI. I have the .Net framework 4 as a prerequisite before EMET gets installed. Not sure what the problem is.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 29, 2013, 5:55am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/134 "2013-08-29T05:55:22Z")

</div>

Here - [http://www.darkoperator.com/blog/2013/8/28/deploying-emet-40-in-small-to-medium-environments-using-wsus.html](http://www.darkoperator.com/blog/2013/8/28/deploying-emet-40-in-small-to-medium-environments-using-wsus.html)

Deploying EMET with WSUS

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [September 11, 2013, 4:48am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/135 "2013-09-11T04:48:23Z")

</div>

bump keep your shit updated and don’t run java applets that randomly pop up

---

<div class="post-metadata">

**Author:** ![boardjnky4](https://avatars.discourse-cdn.com/v4/letter/b/96bed5/32.png) [@boardjnky4](https://forums.speedlife.net/u/boardjnky4)\
**Post date:** [September 11, 2013, 5:33am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/136 "2013-09-11T05:33:09Z")

</div>

new thread, “how to secure vbulletin”

JK, nice job getting us back up and running monkey

---

<div class="post-metadata">

**Author:** ![BOBBYGRV](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@BOBBYGRV](https://forums.speedlife.net/u/BOBBYGRV)\
**Post date:** [September 11, 2013, 6:04am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/137 "2013-09-11T06:04:22Z")

</div>

So I have 2 machines at my home office that just ran out of anti-virus. What should I get for them? One is my laptop and the other is a tower that is in getting a new power supply, fan for the hard drive and a few other things. I was using AVG trial that I had and I refuse to use McAfee ever again. Anybody have a good deal to share at the moment?

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [September 11, 2013, 6:12am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/138 "2013-09-11T06:12:41Z")

</div>

Microsoft Security Essentials its free

---

<div class="post-metadata">

**Author:** ![BOBBYGRV](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@BOBBYGRV](https://forums.speedlife.net/u/BOBBYGRV)\
**Post date:** [September 11, 2013, 6:18am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/139 "2013-09-11T06:18:03Z")

</div>

I like free 🙂

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [September 11, 2013, 6:21am UTC](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335/140 "2013-09-11T06:21:44Z")

</div>

The issue comes down to this all of anti virus vendors are about the same unless you pay for some crazy high end corporate antivirus which is marginally better.

It’s extremely easy to get around anti virus so its only protecting you from shitty hackers/or old stuff

[Previous page](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335.md?page=6)

[Next page](https://forums.speedlife.net/t/securing-your-microsoft-machine/62335.md?page=8)
