i have a remote server running RRAS (to vpn to main server), active directory (child) and dns. It has two network interfaces, one to the private intranet, one with public address.
after a day of activity, lsass.exe shows in the task manager/processes consuming 99 in the cpu field.
is this indicative of an attack? i disabled both the network interfaces and after a few minutes, i got the cpu cycle back to the System Idle process.
any suggestions?
this happens alot. thanks.
R.A. Caluste