D3FEND 技术详情

D3-PLA

D3-PLA

Process Lineage Analysis

定义

Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.

父技术
子技术
关联构件
Process
Process

A process is an instance of a computer program that is being executed. It contains the program code and its current activity. Depending on the operating system (OS), a process may be made up of multiple threads of execution that execute instructions concurrently. A computer program is a passive collection of instructions, while a process is the actual execution of those instructions. Several processes may be associated with the same program; for example, opening up several instances of the same program often means more than one process is being executed.

ProcessTree
Process Tree

A process tree is a tree structure representation of parent-child relationships established via process spawn operations.

语义关系
出向analyzesProcess
出向analyzesProcess Tree
出向kb referenceReference - CAR-2020-11-002: Local Network Sniffing - MITRE
出向kb referenceReference - CAR-2020-11-004: Processes Started From Irregular Parent - MITRE
出向kb referenceReference - CAR-2021-02-002: Get System Elevation - MITRE
出向kb referenceReference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITRE
出向kb referenceReference - CAR-2014-11-008: Command Launched from WinLogon - MITRE
出向kb referenceReference - CAR-2014-11-003: Debuggers for Accessibility Applications - MITRE
出向kb referenceReference - CAR-2019-04-002: Generic Regsvr32 - MITRE
出向kb referenceReference - CAR-2014-11-002: Outlier Parents of Cmd - MITRE
出向kb referenceReference - CAR-2013-02-003: Processes Spawning cmd.exe - MITRE
出向kb referenceReference - CAR-2013-04-002: Quick execution of a series of suspicious commands - MITRE
出向kb referenceReference - CAR-2013-03-001: Reg.exe called from Command Shell - MITRE
出向kb referenceReference - CAR-2014-12-001: Remotely Launched Executables via WMI - MITRE
出向kb referenceReference - CAR-2013-09-005: Service Outlier Executables - MITRE
出向kb referenceReference - CAR-2014-07-001: Service Search Path Interception - MITRE
出向kb referenceReference - CAR-2014-05-002: Services launching Cmd - MITRE
出向kb referenceReference - System and methods thereof for causality identification and attributions determination of processes in a network - Palo Alto Networks IncCyber Secdo Ltd
出向kb referenceReference - System and methods thereof for identification of suspicious system processes - Palo Alto Networks Inc
出向kb referenceReference - CAR-2019-04-001: UAC Bypass - MITRE