lsass.exe

Local Security Authority Process

Microsoft Corporation

It runs as a windows Service named “Encrypting File System (EFS)”.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
Local Security Authority Process

 
Part of the Windows Operating System

Version:
10.0.10240.16384 (th1.150709-1700)

MD5:
c33d357dbb05447fb85b01bb897cad47

SHA-1:
70bbfb8cb36f46b82ed5feb6e04bcc7d70fa511d

SHA-256:
fd4c60e7d5b7e83d2c14d055c56652688baa119e1b411b4a03b607a6b6e1592e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
8/9/2026 8:35:44 AM UTC  (today)

File size:
40.9 KB (41,864 bytes)

Product version:
10.0.10240.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
lsass.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\lsass.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
4/8/2015 3:28:14 PM

Valid to:
7/8/2016 3:28:14 PM

Subject:
CN=Microsoft Windows Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
3300000080E0B6EB3DEB7C8CCB000000000080

File PE Metadata
Compilation timestamp:
7/9/2015 10:24:38 PM

OS version:
10.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.10

CTPH (ssdeep):
768:in65ly4Ga8BVkzd+Ql4Otb70GcA91PikGTP:in65lJGa8XkzdTb70Gc8PikUP

Entry address:
0x3090

Entry point:
E8, 95, 1C, 00, 00, E9, 06, 00, 00, 00, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 10, 8D, 45, F4, C7, 45, F8, 00, 00, 00, 00, 68, 0C, 10, 40, 00, 68, 08, 10, 40, 00, C7, 45, F4, 00, 00, 00, 00, 89, 45, FC, C7, 45, F0, 00, 00, 00, 00, FF, 15, 54, 80, 40, 00, 83, C4, 08, 85, C0, 75, 2F, 8D, 45, FC, 50, 8D, 45, F8, 50, E8, 26, 1C, 00, 00, 68, 04, 10, 40, 00, 68, 00, 10, 40, 00, FF, 15, 50, 80, 40, 00, 8B, 55, FC, 8D, 45, F0, 8B, 4D, F8, 83, C4, 10, 50, E8, 17, 00, 00, 00, B8, FF, 00, 00, 00, 8B, E5...
 
[+]

Entropy:
6.4799

Code size:
22.5 KB (23,040 bytes)

Service
Display name:
Encrypting File System (EFS)

Service name:
EFS

Description:
Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.

Type:
Win32ShareProcess

Depends on:
RPCSS