Windows 10: Blocking credential stealing from lsass VS letting lsass free to operate?

Discus and support Blocking credential stealing from lsass VS letting lsass free to operate? in Windows 10 Gaming to solve the problem; Hi everyone, doubt here:One of the most recommended ASR rule to harden Windows is 'Block credential stealing from the Windows local security authority... Discussion in 'Windows 10 Gaming' started by Adriano Castaldini, Dec 20, 2023.

  1. Blocking credential stealing from lsass VS letting lsass free to operate?


    Hi everyone, doubt here:One of the most recommended ASR rule to harden Windows is 'Block credential stealing from the Windows local security authority subsystem lsass.exe' So, I've set it to WARN, and since then I've received tons of notifications from Defender about that rule. I though it was right because lsass could be somehow vulnerable, so blocking it could be "safer" for my system.On the other hand I've read that lsass is crucial for Windows, and that I should let the process free to work properly.For this reason I tried to set the rule on AUDIT instead of WARN, and since then I neve

    :)
     
    Adriano Castaldini, Dec 20, 2023
    #1

  2. Sasser worm, lsass

    It actually detected a lot, but i believe it was a trojan who was attacking the "lsass" (it was actually from windows, the lsass)

    This trojan was located in "C:/Windows/Temp/svchost.exe", i believe it was this.

    Avg also detected a Adplugin, but i dont believe it was that.
     
    ManéCarvalhaes, Dec 20, 2023
    #2
  3. Smart Card Login not working when LSASS is not disabled

    Hy,

    we are experiencing errors while logging in with Smart Card. Precisely it is error ID 5, but we tried to disable LSASS through Local Group Policy and it worked.

    When LSASS is disabled the Smart Card Login is working normally. The problem is that I do not want to leave LSASS in a disabled state and I don't think that is a solution to the problem.

    Anyone had the same problem maybe?

    All idea's are welcome.
     
    Marko Rukavina, Dec 20, 2023
    #3
  4. Blocking credential stealing from lsass VS letting lsass free to operate?

    Sasser worm, lsass

    So, hi.

    I'm having a problem with what i think it's a "sasser worm", it is attacking a app called "lsass" and making it use 99% of my gpu, when i shut it down in the task manager it gets back to normal, but everytime i restart the PC it comes back, please help me...

    By the way, i'm using windows 10, this started happening today.

    my graphics card is an "asus R9 280", i'm almost sure u don't need to know it, but just to make sure..

    ty.
     
    ManéCarvalhaes, Dec 20, 2023
    #4
Thema:

Blocking credential stealing from lsass VS letting lsass free to operate?

Loading...
  1. Blocking credential stealing from lsass VS letting lsass free to operate? - Similar Threads - Blocking credential stealing

  2. lsass related

    in Windows 10 Gaming
    lsass related: Can anybody tell me what is lsass in windows. Is it a legit program in windows. https://answers.microsoft.com/en-us/windows/forum/all/lsass-related/05410a9b-0839-461e-a6b0-195ec5528bc4
  3. lsass related

    in Windows 10 Software and Apps
    lsass related: Can anybody tell me what is lsass in windows. Is it a legit program in windows. https://answers.microsoft.com/en-us/windows/forum/all/lsass-related/05410a9b-0839-461e-a6b0-195ec5528bc4
  4. Blocking credential stealing from lsass VS letting lsass free to operate?

    in Windows 10 Software and Apps
    Blocking credential stealing from lsass VS letting lsass free to operate?: Hi everyone, doubt here:One of the most recommended ASR rule to harden Windows is 'Block credential stealing from the Windows local security authority subsystem lsass.exe' So, I've set it to WARN, and since then I've received tons of notifications from Defender about that...
  5. LSASS Login Failure

    in Windows 10 Gaming
    LSASS Login Failure: Hello,I could see multiple failed logins from a disabled admin account for the process lsass.exe windows server that is throwing a ton of Login Failure errors. I have dug into the errors and I see that something on the server itself is trying to authenticate with the server...
  6. LSASS Login Failure

    in Windows 10 Software and Apps
    LSASS Login Failure: Hello,I could see multiple failed logins from a disabled admin account for the process lsass.exe windows server that is throwing a ton of Login Failure errors. I have dug into the errors and I see that something on the server itself is trying to authenticate with the server...
  7. LSASS Login Failure

    in Windows Hello & Lockscreen
    LSASS Login Failure: Hello,I could see multiple failed logins from a disabled admin account for the process lsass.exe windows server that is throwing a ton of Login Failure errors. I have dug into the errors and I see that something on the server itself is trying to authenticate with the server...
  8. Lsass using excess Memory

    in Windows 10 Gaming
    Lsass using excess Memory: It appears that I have a memory leak in Lsass.exe. Memory usage keeping getting higher until the computer no longer responds. How can I fix this in Windows 11? https://answers.microsoft.com/en-us/windows/forum/all/lsass-using-excess-memory/301b8a72-f983-4ce2-9ef8-6b1521b6703d
  9. Lsass high cpu

    in Windows 10 Customization
    Lsass high cpu: Hi allI'm Ammar and I have a problem hope you can do something for me.I have windows 10pro and some days ago the problem was started. the Lasass cpu is frequently goes high and low0 to 50% every secondand when I open task manager to see what causes that , the lsass cpu goes...
  10. LSASS High CPU Usage

    in AntiVirus, Firewalls and System Security
    LSASS High CPU Usage: So i accidentaly installed a ransomware and thought that I erased it from my laptop using malwarebytes and windows security, but after malwarebytes said that it was clean after a second run LSASS still uses 30% or more CPU whenever I play RainbowSix. I am currently trying...