Detecttechnique

D3-PSAProcess Spawn Analysis

Process Spawn Analysis

Definition

Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.

Defends against36

TypeTargetConfidenceTier
SubTechniqueAsynchronous Procedure Callt1055.004100%live
SubTechniqueBypass User Account Controlt1548.002100%live
TechniqueSystem Information Discoveryt1082100%live
SubTechniqueCompiled HTML Filet1218.001100%live
SubTechniqueScheduled Taskt1053.005100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
TechniqueMulti-Factor Authentication Request Generationt1621100%live
TechniqueApplication Window Discoveryt1010100%live
TechniqueSystem Service Discoveryt1007100%live
TechniqueXSL Script Processingt1220100%live
SubTechniqueSecurity Account Managert1003.002100%live
SubTechniqueLSA Secretst1003.004100%live
TechniqueWindows Management Instrumentationt1047100%live
SubTechniqueWeb Shellt1505.003100%live
SubTechniqueRundll32t1218.011100%live
SubTechniqueProcess Doppelgängingt1055.013100%live
SubTechniqueLSASS Memoryt1003.001100%live
TechniqueRemote System Discoveryt1018100%live
TechniqueSystem Owner/User Discoveryt1033100%live
TechniqueExploitation for Credential Accesst1212100%live
SubTechniqueCMSTPt1218.003100%live
SubTechniqueAppInit DLLst1546.010100%live
SubTechniqueTransport Agentt1505.002100%live
TechniqueModify Authentication Processt1556100%live
SubTechniqueAppCert DLLst1546.009100%live
TechniqueScheduled Task/Jobt1053100%live
TechniqueProcess Discoveryt1057100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
TechniqueUse Alternate Authentication Materialt1550100%live
SubTechniqueMshtat1218.005100%live

Showing top 30 of 36 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
System Call Analysis
Defence
Script Execution Analysis
Defence
Process Lineage Analysis
Defence
System Init Config Analysis
Defence
Application Protocol Command Analysis
Defence
File Access Pattern Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.