Shellcode: Windows x86 EMET Disable

Strike ID:
S16-u1g01
False Positive:
f
Variants:
1
Year:
2016

Description

This strike transmits a block of shellcode over a UDP socket. This shellcode might be used as part of an exploit payload in order to disable Microsoft Enhanced Mitigation Experience Toolkit (EMET). Disabling EMET would allow an attacker to more easily execute code on the targeted system.

References