Creation of the Policy.vpol file by the lsass.exe process [migrated]
I discovered an EventID 11 (Microsoft-Windows-Sysmon/Operational) event in the Windows logs, in which the Policy.vpol file is created by the process C:\Windows\system32\lsass.exe on behalf of the system user (NT AUTHORITY\System)
How to ch… Continue reading Creation of the Policy.vpol file by the lsass.exe process [migrated]