Microsoft Defender for Endpoint
Endpoint protection

Exploit Protection

In brief

The exploit protection article now links to a revised EMET guidance page and updated previous-version Windows mitigation documentation.

What Defender admins need to know

Administrators using these references will reach the updated source pages; no configuration changes are indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can also use audit mode to evaluate how exploit protection would affect your organization if it were enabled.

Many of the features in the Enhanced Mitigation Experience Toolkit (EMET)Enhanced Mitigation Experience Toolkit (EMET) are included in exploit protection. In fact, you can convert and import existing your EMET configuration profiles into exploit protection. To learn more, see Import, export, and deploy exploit protection configurations.

|Data Execution Prevention (DEP) | Yes | Yes | |Export address filtering (EAF) | Yes | Yes | |Force randomization for images (Mandatory ASLR) | Yes | Yes | |NullPage Security Mitigation | Yes
Included natively in Windows 10 and Windows 11
For more information, see Mitigate threats by using Windows 10 security featuresMitigate threats by using Windows 10 security features | Yes | |Randomize memory allocations (Bottom-Up ASLR) | Yes | Yes | |Simulate execution (SimExec) | Yes | Yes | |Validate API invocation (CallerCheck) | Yes | Yes | |Validate exception chains (SEHOP) | Yes | Yes | |Validate stack integrity (StackPivot) | Yes | Yes | |Certificate trust (configurable certificate pinning) | Windows 10 and Windows 11 provide enterprise certificate pinning | Yes | |Heap spray allocation | Ineffective against newer browser-based exploits; newer mitigations provide better protection
For more information, see Mitigate threats by using Windows 10 security featuresMitigate threats by using Windows 10 security features | Yes | |Block low integrity images | Yes | No | |Code integrity guard | Yes | No | |Disable extension points | Yes | No | |Validate image dependency integrity | Yes | No |