The FireEye Endpoint Security Process Guard Module protects endpoints from common credential theft attacks. Process Guard prevents attackers from obtaining access to credential data, or key material stored within the Local Security Authority Subsystem Service (LSASS) process.
Process Guard detects or blocks access requests to the critical LSASS process that contains credential data. An event is sent to the Endpoint Security controller and can be viewed in the Process Guard Module home page. This page helps administrators to analyze and troubleshoot any potential compatibility issues. By default, Process Guard detects all processes accessing credential data without blocking them. The agent module is applied to host sets, rather than individual hosts.
Process Guard provides an allow list feature that permits administrators to bypass detection, or to block an action. This alleviates any issues with legitimate applications that require full system access to perform normal operations.