Detectsubtechnique

D3-PLAProcess Lineage Analysis

Definition

Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.

Defends against14

TypeTargetConfidenceTier
TechniqueUse Alternate Authentication Materialt1550100%live
SubTechniqueLSASS Memoryt1003.001100%live
TechniqueSystem Owner/User Discoveryt1033100%live
TechniqueExploitation for Credential Accesst1212100%live
SubTechniqueDisable or Modify Toolst1562.001100%live
SubTechniqueTransport Agentt1505.002100%live
TechniqueScheduled Task/Jobt1053100%live
SubTechniqueSecurity Account Managert1003.002100%live
TechniqueMulti-Factor Authentication Request Generationt1621100%live
SubTechniqueNetsh Helper DLLt1546.007100%live
TechniqueModify Authentication Processt1556100%live
SubTechniqueScheduled Taskt1053.005100%live
SubTechniqueLSA Secretst1003.004100%live
SubTechniqueWeb Shellt1505.003100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Process Spawn Analysis
Defence
System Call Analysis
Defence
File Access Pattern Analysis
Defence
IPC Traffic Analysis
Defence
Application Protocol Command Analysis
Defence
Script Execution Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.