Microsoft Defender for Endpoint
Endpoint protection

Microsoft Defender for Endpoint Exploit protection (EP) demonstrations

In brief

The article now includes an overview, more explicit PowerShell commands for applying and verifying mitigation policies, and steps for converting EMET XML profiles and applying self-hosted XML settings.

What Defender admins need to know

Administrators can use the updated procedures to configure, troubleshoot, and verify Exploit Protection demonstrations more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Exploit protection (EP) demonstrations

Overview

This article walks you through demonstration scenarios for configuring Exploit Protection, applying mitigation settings, and converting existing EMET profiles in Microsoft Defender for Endpoint.

Exploit Protection automatically applies exploit mitigation settings system wide and on individual apps. Many of the features in the Enhanced Mitigation Experience Toolkit (EMET) have been included in Exploit Protection, and you can convert and import existing EMET configuration profiles into Exploit Protection.

Set up the demo environment

  1. RunApply the process mitigation policy from the XML configuration file by running the following PowerShell commands:command:

    Set-ProcessMitigation -PolicyFilePath ProcessMitigation.xml
    
  2. To view usage and parameter information for customizing or troubleshooting the policy application, run the following command:

    Set-ProcessMitigation –help
    
  3. Verify configurationthat the mitigation policy was applied successfully by listing the current process mitigation settings:

     Get-ProcessMitigation
    

Sample xmlXML file for exploit protection settings

EP xml config file (right select, "save target as")

Scenario 1: Convert EMET xml to Exploit Protection settings

Use the following steps to convert an EMET XML configuration file to Exploit Protection settings:

  1. Convert EMET to xml, run PowerShell command:

    ConvertTo-ProcessMitigationPolicy
    
  2. Apply settings,settings using the XML file generated by ConvertTo-ProcessMitigationPolicy, run PowerShell command:use the XML from the prior step

    Set-ProcessMitigation -PolicyFilePath
    

Scenario 2: Apply selfhost xml to Exploit Protection settings

Follow these steps to apply a self-hosted XML configuration to Exploit Protection settings:

  1. Download our EP xml config file (right select, "save target as") or use your own.

  2. Apply settings, run PowerShell command:

  3. Review the event log for application compatibility.

See alsoRelated content

Exploit Protection documentation

Microsoft Defender for Endpoint - demonstration scenarios