Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ED
Advisor

lsass.exe infection found by Anti-Malware. Unable to exclude

Hi everyone,

This is the situation. Endpoint security finds lsass.exe as an infection and cures it when RDP to a server. 

 

image.png

image.png

image.png

 

I have tried to exclude but it doesn't help

image.png

 

Any suggestions and also why does it react like this for RDP? Low confidence and low severity. 

0 Kudos
1 Reply
Kobie_Bendalak
Employee Alumnus
Employee Alumnus

Please raise a TAC ticket to have it investigated, seems like an FP.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events