How to Identify URL or document after EMET Mitigation?

Hi,
is there a way to identify which URL was requested in the Browser or which document was opened in Office or Adobe Reader when EMET triggers a mitigation?
This is an important information missing in the logs and there are probably technical reasons for it (which?) but maybe there is a way of (ideally automatically) getting/correlating this information from somewhere.
Thanks for any hints or thoughts. 

In EMET 5.0 a tooltip was shown in the taskbar notification area when you visted a site (in the internet zone) in the browser which uses Java and a event was written to the Windows Event Log which sometimes specified the web address. Below are two examples:
          EMET detected ASR mitigation in iexplore.exe
          ASR check failed:
            Application     : C:\Program Files\Internet Explorer\iexplore.exe
            User Name     : COMP\USERNAME
            Session ID     : 2
            PID         : 0x109C (4252)
            TID         : 0x16BC (5820)
            Module     : jp2iexp.dll
          EMET detected ASR mitigation in iexplore.exe
          ASR check failed:
            Application     : C:\Program Files\Internet Explorer\iexplore.exe
            User Name     : COMP\USERNAME
            Session ID     : 2
            PID         : 0x1710 (5904)
            TID         : 0xA20 (2592)
            Module     : jp2iexp.dll
            Web address     : http://java.server1.company.com/java/module/
            Url zone     : Trusted
With EMET 5.1 this doesn't seem to happen anymore and Internet Explorer just reports that the website uses Java which can be downloaded and installed.
When I open a Word document with Shockwave Flash Object I get this tooltip
and this event is written in the application event log.
          Log Name:      Application
          Source:        EMET
          Date:          26-11-2014 9:35:54
          Event ID:      1
          Task Category: None
          Level:         Warning
          Keywords:      Classic
          User:          N/A
          Computer:      xxxx
          Description:
          EMET detected ASR mitigation in WINWORD.EXE
          ASR check failed:
            Application     : C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
            User Name     : Domain\User
            Session ID     : 3
            PID         : 0xEF4 (3828)
            TID         : 0x130C (4876)
            Module     : Flash32_15_0_0_239.ocx
The name of the document is not mentioned in this.
My suggestion is to fill in a feedback form (https://connect.microsoft.com/emet/feedback/LoadSubmitFeedbackForm) on the Microsoft Connect portal for the EMET 5.0 feedback program.
W. Spu

Similar Messages

  • How to identify the related job, after sheduling a infopackage?

    Hi,
       Anybody explain that how to identify the related job after scheduling a infopackage in the BW system?

    Hi Aditya,
    Goto SM37->Search Job BI_BTCH*
    Job Prefix.
    http://help.sap.com/saphelp_nw70ehp1core/helpdata/en/da/0318025d64a84b94542641ed77ee74/content.htm
    Hope it helps.
    Thanks and Regards,
    MuraliManohar.
    Edited by: Muralimano on Jun 5, 2011 9:38 AM

  • How to Change URL of BPA after clicking on Open Document in PO Notification for India Localization?

    In the Purchase Order Approval workflow notification , there are two links at the bottom of page under heading REFERENCES,
    - view PDF
    - open document
    So when we click on open document, the Oracle Forms loads and  purchase order screen will appear in the screen.
    In case of India localization, for standard PO the India local screen opens, where we can see the taxes by clicking on Taxes Button.
    But in case of blanket purchase agreements, when we click on open document link from the notification,we are routed to the application with the screen of global purchase order, instead it
    should go to Purchase Orders(Localization).
    We want to move to the India local po screen for BPA.
    So please let me know, where I can change the URL for Blanket Purchase Agreements.
    Regards
    Sandeep

    Hi kalyani,
    Please check my inbound plug code...tell me what changes wee need to do and where wee need to add this code...once again thanks for your reply..
    METHOD
    ip_inboundplug.
    **CALL METHOD SUPER->IP_INBOUNDPLUG
    ** EXPORTING
    ** iv_collection = iv_collection.
    DATA: lt_ivr_url_param TYPE tihttpnvp,
    ls_ivr_url_param TYPE ihttpnvp,
    lr_searchcustomer TYPE REF TO if_bol_bo_property_access,
    ls_searchcustomer TYPE crmt_bupa_il_header_search.
    CALL METHOD cl_crm_ui_session_manager=>get_initial_form_fields
    CHANGING
    cv_fields = lt_ivr_url_param.
    lr_searchcustomer ?= me->typed_context->searchcustomer->collection_wrapper->get_current( ).
    CHECK lr_searchcustomer IS BOUND.
    READ TABLE lt_ivr_url_param INTO ls_ivr_url_param WITH KEY name = 'sap-phoneno'. "'sap-phoneno'.
    IF ls_ivr_url_param-value IS NOT INITIAL.
    ls_searchcustomer-telephone = ls_ivr_url_param-value.
    CALL METHOD lr_searchcustomer->set_properties( EXPORTING is_attributes = ls_searchcustomer ).
    eh_onsearch( ).
    ENDIF.
    ENDMETHOD

  • How to identify and delete objects after failure of registering XML schema

    Hi,
    I have tried to register a XML schema with many global elements but failed.
    I have checked the view DBA_XML_SCHEMA and found that there is an entry for this failed XML schema and the disk spaces would not be freed after the failure of registration as well.
    I have tried DBMS_XMLSCHEMA.deleteSchema() with DELETE_CASCADE_FORCE but failed with ORA-31000: Resource is not XDB document.
    How can I identify and delete the objects for this failed XML schema and free up the disk space ?
    I would not prefer to use 'DROP USER ... CASCADE' since there are other objects owned by this user.
    Thanks in advance.

    you can get them from user_objects.
    but you have to identify them manuallly if your schema has other objects other then created by the xml schema creation process.
    Note these objects will be cases senistitive. so you should enclose them with double quotes during deletion.

  • How to stop Acrobat opening document after printing to PDFmaker?

    Hello,
    When I print to PDFmaker, I just want Acrobat (Professional 7.0) to save the document, but it insists on opening a new window containing the recently printed document. If I quickly open another window, it brings the document window back to the top.
    This is very irritating. How do I make it stop opening this unnecessary window?
    Thanks,
    Katie
    PS. If relevant, I am running Windows XP on a Dell Inspiron 1520.

    From your Start Menu select Printers and Faxes. Right click on the listing for Adobe PDF and click Printing Preferences... and go to the Adobe PDF Settings tab. Uncheck the box labeled View Adobe PDF results. Click OK.

  • How can I save PDF document after Digital signature ?

    I am using adobe reader and after signing the document (Digital signature) I can not save the document.

    What is your operating system?  What is your Reader version?
    I probably won't have an answer for you, but the information may help somebody else who might.

  • How to restore a parked document after the reverse of the posted document?

    Hi All,
    I've created a parked document; later I've posted it.
    But I was wrong; now I've to reverse the document posted. Is there a way to restore the parked document?
    Thanks

    Hi
    Once FI Document Generated from park document, we con't revert back to park document.
    Regards
    Viswa

  • What do I do to open a document after I convert a PDF to Word

    How do I open a document after I convert a
    PDF to a word document?

    You need Micosoft Publisher.
    I have seen a suggestion that you can send a .pub file here 
    https://www.pdfonline.com/convert_PDF.asp.
    to get it converted for free to pdf if it is less then 2MB. Bigger files need to be payd
    The link works but I have not tested the conversion.

  • Cancelling material document after usage decision

    hi experts,
    how to cancell a material document after usage decision has been made (quality to unresricted stock).
    thanks in advance
    regards
    jai

    Hi,
    whenever you do cancellation for material doument then its always done for the same stock type for which you have made GR....
    If you wanna do from it then Choose cancellation and material doc and enter the mrtl doc no.
    and execute ...
    Hope it helps..
    Regards,
    Priyanka.P
    AWARD IF HELPFULL

  • How to identify the version of InDesign application used to produce an InDesign document

    Is there a way to identify the version of the InDesign application(CS/CS2/CS3) where the Document was originally created?
    Can we use InDesign CS3 server to open a CS2 document to do some relinking and save it again as a CS2 document without converting the document to CS3 version? If not, how to identify and not open the documents produced by previous versions of InDesign application?
    Thanks in advance.

    Hi,
    you can test the Creator. In addition however the document must be opened. If it is a CS2 document, closes document again without to save. I did not test it. Would have to function however.
    JavaScript Example:
    try {
    var creator = app.documents.item(0).metadataPreferences.creator;
    catch(e){}
    alert( "The creator = " + creator );
    Greeting Andreas

  • How to identify which is rootsite/webapplication url and which are site collection url ?

    How to identify which is rootsite/webapplication url and which are site collection url underneath of web application using powershell script in following code?
    # Get site objects
    $webapplication = Get-SPWebApplication $siteUrl
    # Walk through each site in the site collection
    foreach($site in $webapplication.Sites)
    foreach($subWeb in $site.AllWebs)
    $_ = AddLevel123($subWeb.Url)

    Hi,
    Hope you wanted to know which API is Site collection (SPSite) and Sub site(SPWeb) 
    $webapplication.Sites = Site Collection (SPSite)
    and $site.AllWebs = Subsite (SPWeb)
    and see these links - to get webApplication URL
    http://social.msdn.microsoft.com/Forums/sharepoint/en-US/e223b607-ab35-454a-a050-1db3005687e5/spwebapplication-url?forum=sharepointdevelopmentlegacy
    SPSite Url - SPSite.Url (http://msdn.microsoft.com/en-us/library/office/microsoft.sharepoint.spsite.url.aspx)
    SPweb URl - SPWeb.URL (http://msdn.microsoft.com/en-us/library/office/microsoft.sharepoint.spweb.url.aspx)
    http://social.technet.microsoft.com/Forums/sharepoint/en-US/b4dfb645-69f4-4abd-947c-64ca42af3a26/script-to-get-list-of-sites-and-subsites
    Hope this helps!
    MCITP: SharePoint 2010 Administrator
    MCTS - MOSS 2007 Configuring, .NET 2.0
    | SharePoint Architect | Evangelist |
    http://www.sharepointdeveloper.in/
    http://ramakrishnaraja.blogspot.com/

  • How to edit my document after signing?

    how to edit my document after signing?

    Hi fortm71591551,
    Follow the below procedure for editing your document after signing it:
    1. Open the File in Acrobat
    2. Right Click on the signature field and choose 'Clear Signature'
    3. Go to tools pane on the right side of the window then choose 'Edit' Under Forms Drop Down Menu.
    4. Right Click on the signature field  and choose delete.
    5. Click 'Close Form editing' and then you can make necessary changes and resign your pdf (If you want to).
    Hope that helps.
    Please revert back for any other query or if you need any further assistance.
    Regards,
    Rahul

  • How do I keep URLs from printing after Events?

    Version 3.0.8 (1287) - How do I keep URLs from printing after Events?

    Open the Pages preferences > uncheck Automatic detect email and web addresses

  • How can I unactivate a form in a pdf so I can share an uncustomizable document after filling it?

    How can I unactivate a form in a pdf so I can share an uncustomizable document after filling it?

    Thanks George, this seem to be what I was looking for!
    But when I try to flatten the pdf I get the following message : "security settings for digital signatures in this file prevent flattening"
    I try to save a copy and change the security settings and it still doesnt work... what I'm missing here?
    Thanks

  • How do I retrieve AW 6 documents after upgrading to Lion?

    How do I retrieve AW 6 documents after upgrading to Lion?

    Find someone who backed up their 10.6 or is still running 10.6 who has Appleworks and Filemaker Pro who will convert the data for you, or if you have a backup, which you should always have when upgrading, downgrade to your backup first, convert the necessary files, then upgrade.  See my http://www.macmaps.com/backup.html FAQ* on how to backup if you don't know how.

Maybe you are looking for

  • Wily Introscope 8.2.2 - No License for Wrapper service

    Hi All, I've installed the Wily Introscope Manager 8.2.2. When starting the EM service, I get the following error message in the log file: STATUS | wrapper  | 2010/09/20 15:10:47 | --> Wrapper Started as Service STATUS | wrapper  | 2010/09/20 15:10:4

  • BPM Send Step with acknowledgment: ID: sender agreement?

    Hello everybody, I have a send step in BPM and I expect a acknowledgement from the receiver. Do I have to configure a sender agreement? Thanks a lot Regards Mario

  • Iphone to play mp3 over car speakers

    What do i need to be able to do this? Also, is there a car place holder i can purchase for iphone.

  • Missing Audio from FCP

    I have a sequence that I'm sending to Soundtrack Pro from Final Cut Pro. It sends and opens but I notice that there is audio missing from sections where I have .motn elements in my timeline. The audio is there in FCP... Is there a solution to this?

  • Populate fields when creating an new record

    Hello, When I create a new record from an other record type (ex: a service request from a task), I would like to pre populate some fields which are common to the task and the SR (ex: Owner, Account, Contact) and already on the task record. I have rea