Microsoft Defender scores full marks in Win11 LSASS credential dump protection test

time:2023-03-24 10:24:17 source:scripttoolbox.com author:Monitor
Microsoft Defender scores full marks in Win11 LSASS credential dump protection test

IT House September 10 news, security assessment company AV-Comparatives conducted LSASS credential dump protection tests for enterprise-level anti-malware solutions. Among the products tested, Microsoft's Defender for Endpoint received a perfect score. Briefly, dump credentials in LSASS (Local Security Authority Subsystem Service): LSASS is a process in the Windows operating system that is responsible for enforcing security policies on the system. It authenticates users logged into a Windows computer or server, handles password changes, and creates access tokens. After a user logs in, various credentials are generated and stored in the local security authorization subsystem service LSASS process in memory so that the user does not have to log in repeatedly each time they access system resources. For this reason, attackers often use the LSASS process to steal useful credentials from domain users via dumps. Then use it to run rampant in the target network. In this test, testers used 15 different attack methods, and Defender for Endpoint blocked them well. In addition, Avast Ultimate Business Security, Bitdefender GravityZone Business Security Enterprise, Kaspersky EDR Expert also passed the test perfectly.

(Responsible editor:Small parts)

Related content