Forum Discussion

GuruLee's avatar
GuruLee
Brass Contributor
May 08, 2024

LSASS Memory Dump Handle Access - poqexec.exe ?

We are seeing SIEM alerts for LSASS Memory Dump Handle Access for the 'C:\Windows\System32\poqexec.exe' process (Primitive Operations Queue Executor) on several endpoints with the computer account na...