The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Module Overview‌

Prev Next

The FireEye Endpoint Security Process Guard Module protects endpoints from common credential theft attacks. Process Guard prevents attackers from obtaining access to credential data, or key material stored within the Local Security Authority Subsystem Service (LSASS) process.

Process Guard detects or blocks access requests to the critical LSASS process that contains credential data. An event is sent to the Endpoint Security controller and can be viewed in the Process Guard Module home page. This page helps administrators to analyze and troubleshoot any potential compatibility issues. By default, Process Guard detects all processes accessing credential data without blocking them. The agent module is applied to host sets, rather than individual hosts.

Process Guard provides an allow list feature that permits administrators to bypass detection, or to block an action. This alleviates any issues with legitimate applications that require full system access to perform normal operations.