Link to home
Start Free TrialLog in
Avatar of Jeff Sniff
Jeff Sniff

asked on

VDI (lsass.exe) security alert

We have a VDI environment and receiving the following error:

Cisco AMP alert:  lsass.exe (high alert)

Reason: Process module is not clean and not signed
File full path: C:\Windows\System32\lsass.exe

Up until a couple of weeks ago, we were not receiving this alert or maybe the Cisco AMP got introduced into this environment.  I see multiple alerts for only our VDI machines and not seeing the alert for our other machines.  How can I determine this is valid or not?
Avatar of Dirk Kotte
Dirk Kotte
Flag of Germany image

i would try to compare the files lsass.exe between VDI and physical device.
(you need the same OS-version and patchlevel)
Please let us know the result ...

https://www.diffnow.com/compare-files
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.