May 17 2022 12:36 AM
Hi,
We want to apply the ASR rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' with exceptions for a trusted executable as the source app. However, it looks like the exceptions list only applies to the detected file, which is always lsass.exe.
Is there a way to effect an allow-list for this rule?
Thanks.
May 17 2022 06:18 AM
Solution