Skip to content
Back to skills

Implementing Memory Protection With Dep Aslr

ASecurity

'Implements memory protection mechanisms including DEP (Data Execution

  • 67 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 4, 2026
devopsshellsecurity

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills --skill implementing-memory-protection-with-dep-aslr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Implementing Memory Protection With Dep Aslr?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Implementing Memory Protection With Dep Aslr
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/costrict-plugins-repo-implementing-memory-protection-with-dep-aslr/badge)](https://www.skillsdirectory.com/skills/costrict-plugins-repo-implementing-memory-protection-with-dep-aslr)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: implementing-memory-protection-with-dep-aslr
description: 'Implements memory protection mechanisms including DEP (Data Execution
  Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard),
  and other exploit mitigations to prevent memory corruption attacks. Use when hardening
  endpoints against buffer overflow exploits, ROP chains, and code injection. Activates
  for requests involving memory protection, exploit mitigation, DEP, ASLR, or CFG
  configuration.

  '
domain: cybersecurity
subdomain: endpoint-security
tags:
- endpoint
- memory-protection
- DEP
- ASLR
- exploit-mitigation
- CFG
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- PR.PS-02
- DE.CM-01
- PR.IR-01
mitre_attack:
- T1055
- T1547
- T1059
- T1036
- T1190
---
# Implementing Memory Protection with DEP and ASLR

## When to Use

Use this skill when hardening endpoints against memory-based exploits by configuring DEP, ASLR, CFG, and Windows Exploit Protection system-wide and per-application mitigations.

## Prerequisites

- Windows 10/11 or Windows Server 2016+ with administrative privileges
- Group Policy management access for enterprise-wide deployment
- Understanding of memory corruption attack techniques (buffer overflow, ROP chains)
- Test environment for validating application compatibility with exploit mitigations

## Workflow

### Step 1: Configure System-Level Mitigations

```powershell
# Enable system-wide DEP (Data Execution Prevention)
# Boot configuration: OptIn (default), OptOut (recommended), AlwaysOn
bcdedit /set nx AlwaysOn

# Verify ASLR status (enabled by default on modern Windows)
Get-ProcessMitigation -System
# MandatoryASLR, BottomUpASLR, HighEntropyASLR should be ON

# Enable all system-level mitigations
Set-ProcessMitigation -System -Enable DEP,SEHOP,ForceRelocateImages,BottomUp,HighEntropy
```

### Step 2: Configure Per-Application Mitigations

```powershell
# Harden high-risk applications (browsers, Office, PDF readers)
Set-ProcessMitigation -Name "WINWORD.EXE" -Enable DEP,SEHOP,ForceRelocateImages,CFG,StrictHandle
Set-ProcessMitigation -Name "EXCEL.EXE" -Enable DEP,SEHOP,ForceRelocateImages,CFG,StrictHandle
Set-ProcessMitigation -Name "AcroRd32.exe" -Enable DEP,SEHOP,ForceRelocateImages,CFG
Set-ProcessMitigation -Name "chrome.exe" -Enable DEP,CFG,ForceRelocateImages
Set-ProcessMitigation -Name "msedge.exe" -Enable DEP,CFG,ForceRelocateImages

# Export configuration for deployment
Get-ProcessMitigation -RegistryConfigFilePath "C:\exploit_protection.xml"
# Deploy via Intune or GPO
```

### Step 3: Deploy via Intune/GPO

```
Intune: Endpoint Security → Attack Surface Reduction → Exploit Protection
  Import exploit_protection.xml template

GPO: Computer Configuration → Admin Templates → Windows Components
  → Windows Defender Exploit Guard → Exploit Protection
  → "Use a common set of exploit protection settings" → Enabled
  → Point to XML file on network share
```

## Key Concepts

| Term | Definition |
|------|-----------|
| **DEP** | Marks memory pages as non-executable to prevent shellcode execution in data regions |
| **ASLR** | Randomizes memory addresses of loaded modules to defeat hardcoded ROP gadgets |
| **CFG** | Validates indirect call targets at runtime to prevent control flow hijacking |
| **SEHOP** | Validates SEH chain integrity to prevent SEH-based exploitation |

## Tools & Systems
- **Windows Exploit Protection**: Built-in per-process mitigation management
- **EMET (legacy)**: Enhanced Mitigation Experience Toolkit (predecessor, now deprecated)
- **ProcessMitigations PowerShell**: Get/Set-ProcessMitigation cmdlets

## Common Pitfalls
- **DEP compatibility**: Legacy 32-bit applications may crash with DEP AlwaysOn. Use OptOut with exceptions.
- **Mandatory ASLR breaking apps**: Some applications are not ASLR-compatible. Test before enforcing ForceRelocateImages.
- **CFG limited to compiled-in support**: CFG only works for applications compiled with /guard:cf. Cannot be retroactively applied.

Files in this skill

  • LICENSE11 KB
  • SKILL.md3.9 KB
  • assets/template.md553 B
  • references/api-reference.md1.8 KB
  • references/standards.md316 B
  • references/workflows.md374 B
  • scripts/agent.py6.4 KB
  • scripts/process.py1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…