Preventive Protection event: Open protected process
id: 14773, timestamp: 03.05.2024 17:52:27.0054, type: PsOpenProcess (18), flags: 1 (wait: 1)
sid: S-1-5-21-3252088687-286974686-1753256928-1001, cid: 6320/3968:\Device\HarddiskVolume5\Windows\System32\Taskmgr.exe
context: start addr: 0x00007FF60A7BE0D0, image: 0x00007FF60A790000:\Device\HarddiskVolume5\Windows\System32\Taskmgr.exe
unique id: 6320-133592215469897237-140694714384384
behaviour: run_as_auto_elevated
request by: \Device\HarddiskVolume5\Windows\System32\Taskmgr.exe:6320
fileinfo: size: 1214904, easize: 404, attr: 0x20, buildtime: 21.03.1920 08:00:16.0000, ctime: 14.03.2024 17:01:41.0889, atime: 03.05.2024 17:52:26.0702, mtime: 14.03.2024 17:01:41.0936, descr: Task Manager, ver: 10.0.19041.4123 (WinBuild.160101.0800), company: Microsoft Corporation, oname: Taskmgr.exe
signer: C=US|ST=Washington|L=Redmond|O=Microsoft Corporation|CN=Microsoft Windows, issuer: C=US|ST=Washington|L=Redmond|O=Microsoft Corporation|CN=Microsoft Windows Production PCA 2011, timestamp: 22.02.2024 05:16:17.0000, thumbprint: d8fb0cc66a08061b42d46d03546f0d42cbc49b7c, eku: unknown [28], flags: 0x2a, hash alg: Sha256
catfile: {f750e6c3-38ee-11d1-85e5-00c04fc295ee}\microsoft-windows-client-desktop-required-package0514~31bf3856ad364e35~amd64~~10.0.19041.4170.cat
creator name: Microsoft Windows
creator url:
http://www.microsoft.com/windows
file sha1: cd97fd1e83174314ed091457e8c640ca3928bf78
file sha256: 78a68d19ef89ef39b26a85d5948d3a5051568674e2a4842ba10e3ddcb68eee6e
status: db_cert_white_list, signed_catroot, sfc, pe64, spc, system_file_auto_elevated / signed_catroot / unknown / taskmgr / white / unknown
target process: \Device\HarddiskVolume5\Windows\System32\lsass.exe:644
type: 5, reason: 0x1, access: 0x1410
fileinfo: size: 60640, easize: 404, attr: 0x20, buildtime: 12.09.2009 04:49:51.0000, ctime: 10.04.2024 11:41:52.0020, atime: 03.05.2024 17:06:43.0037, mtime: 10.04.2024 11:41:52.0025, descr: Local Security Authority Process, ver: 10.0.19041.4239 (WinBuild.160101.0800), company: Microsoft Corporation, oname: lsass.exe
signer: C=US|ST=Washington|L=Redmond|O=Microsoft Corporation|CN=Microsoft Windows Publisher, issuer: C=US|ST=Washington|L=Redmond|O=Microsoft Corporation|CN=Microsoft Windows Production PCA 2011, timestamp: 18.03.2024 03:00:48.0000, thumbprint: 09a1aa05288e952c901821deaece78d148d2e4d2, eku: unknown [28], flags: 0x2a, hash alg: Sha256
catfile: {f750e6c3-38ee-11d1-85e5-00c04fc295ee}\microsoft-windows-client-desktop-required-package0516~31bf3856ad364e35~amd64~~10.0.19041.4291.cat
creator name: Microsoft Windows
creator url:
http://www.microsoft.com/windows
file sha1: 83ebb66f070956225959ee773b468f89ed55479c
file sha256: efa9e8325232bbd3f9a118d396de04370e56c3c7b6d552fab46b5b39f3ad522d
status: signed_catroot, sfc, pe64, spc / signed_catroot / unknown / lsass / unknown / unknown
attempt to read the memory of a protected process ==> denied
id: 14773 ==> denied [5], time: 0.173800 ms