- Nov 15, 2016
- 867
Note, since Windows 8.1 you can optionally opt-in to make lsass.exe a protected process. This is a really good idea by the way because lsass.exe has been attacked before for credential theft.
Configuring Additional LSA Protection
I recommend to everyone to do this but only if you understand how it works to prevent potential problems.
It should be mentioned that to attack lsass.exe normally, you'd need to be running with elevation anyway... and thus if you had administrator rights, you could always forcefully disable the protection via registry modification, but it is unlikely this would happen in the real world anyway. I've never seen a malware sample actually do this in the wild yet.
I configured the additional protection following the registry key.
Interesting article, the author used mimikatz in a test against LSA protection and Credential Guard.
Poking Around With 2 lsass Protection Options – Red Teaming with a Blue Team Mentaility – Medium