Windbg

!process 0 0 lsass.exe

dt nt!_EPROCESS ADDR

Protecting processes such as lsass.exe

dt nt!_EPROCESS ffffcb01e111e080 Protection

Protected Process Light Internals

_PS_PROTECTION
  +0x000 Level            : UChar
  +0x000 Type             : Pos 0, 3 Bits
  +0x000 Audit            : Pos 3, 1 Bit
  +0x000 Signer           : Pos 4, 4 Bits