Skip to content

NTOP Shows Windows Services running with GMSA account owners as running with SYSTEM account #79

@GauravES

Description

@GauravES

We have some Windows Services running with AD GMSA accounts of the form domain\gmsa_string$

(https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-managed-service-accounts/group-managed-service-accounts/group-managed-service-accounts-overview )

NTOP shows the Windows Service running as SYSTEM, while Windows own Task manager, services.msc and other process manager tools such as Process Hacker show them running with the correct gmsa account.

However we also have some IIS Pools running with the same GMSA Account and for them NTOP shows the correct GMSA account. So it seems for some processes it is able to detect the correct GMSA process owner, but not for all

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions