Hide last authors
S F 1.1 1 {{aagon.priorisierung}}
S F 4.1 2 10
S F 1.1 3 {{/aagon.priorisierung}}
S F 5.1 4
Jannis Klein 41.2 5 When the agent service is restarted, the threats or alerts with Event IDs 1121 and 1122 may be triggered on the agent.
6 These events occur because the ASR rule „[['Block the theft of Windows Local Security Authority credentials'>>doc:ACMP.64.ACMP-Solutions.Security.Defender Management.Konfigurationsprofile.Konfigurationsprofil-Einstellungen.WebHome]]“ intervenes. This rule prevents direct access to LSASS memory by untrusted processes. So if a process tries to access LSASS using the OpenProcess() function with PROCESS_VM_READ permissions, the ASR rule will block that access.
S F 5.1 7
S V 20.1 8 {{figure}}
S F 6.1 9 (% style="text-align:center" %)
S V 20.1 10 [[image:ereigniseigenschaften_1121_zoom80.png]]
S V 18.1 11
S V 20.1 12 {{figureCaption}}
Jannis Klein 41.2 13 Event properties - Event 1121
S V 20.1 14 {{/figureCaption}}
15 {{/figure}}
S F 5.1 16
Jannis Klein 41.2 17 You can work around this blockage by adding lsass.exe as either an entire directory or file path in //Configuration Profiles// > //ASR Rule Exclusions//. Then select the //Exclude files and paths from ASR rules// checkbox.

Navigation

© Aagon GmbH 2024
Besuchen Sie unsere neue Aagon-Community