D3FEND 技术详情
D3-PSA
定义
Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.
父技术
子技术
关联构件
CreateProcess
Create Process
Executes a process.
Process
Process
A process is an instance of a computer program that is being executed. It contains the program code and its current activity. Depending on the operating system (OS), a process may be made up of multiple threads of execution that execute instructions concurrently. A computer program is a passive collection of instructions, while a process is the actual execution of those instructions. Several processes may be associated with the same program; for example, opening up several instances of the same program often means more than one process is being executed.
语义关系
出向analyzesCreate Process
出向analyzesProcess
出向kb referenceReference - CAR-2019-08-002: Active Directory Dumping via NTDSUtil - MITRE
出向kb referenceReference - CAR-2020-04-001: Shadow Copy Deletion - MITRE
出向kb referenceReference - CAR-2020-05-003: Rare LolBAS Command Lines - MITRE
出向kb referenceReference - CAR-2020-08-001: NTFS Alternate Data Stream Execution - System Utilities - MITRE
出向kb referenceReference - CAR-2020-09-003: Indicator Blocking - Driver Unloaded - MITRE
出向kb referenceReference - CAR-2020-09-004: Credentials in Files & Registry - MITRE
出向kb referenceReference - CAR-2020-11-001: Boot or Logon Initialization Scripts - MITRE
出向kb referenceReference - CAR-2020-11-003: DLL Injection with Mavinject - MITRE
出向kb referenceReference - CAR-2020-11-005: Clear Powershell Console Command History - MITRE
出向kb referenceReference - CAR-2020-11-006: Local Permission Group Discovery - MITRE
出向kb referenceReference - CAR-2020-11-007: Network Share Connection Removal - MITRE
出向kb referenceReference - CAR-2020-11-008: MSBuild and msxsl - MITRE
出向kb referenceReference - CAR-2020-11-009: Compiled HTML Access - MITRE
出向kb referenceReference - CAR-2021-01-002: Unusually Long Command Line Strings - MITRE
出向kb referenceReference - CAR-2021-01-003: Clearing Windows Logs with Wevtutil - MITRE
出向kb referenceReference - CAR-2021-01-004: Unusual Child Process for Spoolsv.Exe or Connhost.Exe - MITRE
出向kb referenceReference - CAR-2021-01-006: Unusual Child Process spawned using DDE exploit - MITRE
出向kb referenceReference - CAR-2021-01-007: Detecting Tampering of Windows Defender Command Prompt - MITRE
出向kb referenceReference - CAR-2021-01-008: Disable UAC - MITRE
出向kb referenceReference - CAR-2021-01-009: Detecting Shadow Copy Deletion via Vssadmin.exe - MITRE
出向kb referenceReference - CAR-2021-02-001: Webshell-Indicative Process Tree - MITRE
出向kb referenceReference - CAR-2021-04-001: Common Windows Process Masquerading - MITRE
出向kb referenceReference - CAR-2021-05-001: Attempt To Add Certificate To Untrusted Store - MITRE
出向kb referenceReference - CAR-2021-05-002: Batch File Write to System32 - MITRE
出向kb referenceReference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITRE
出向kb referenceReference - CAR-2021-05-004: BITS Job Persistence - MITRE
出向kb referenceReference - CAR-2021-05-005: BITSAdmin Download File - MITRE
出向kb referenceReference - CAR-2021-05-006: CertUtil Download With URLCache and Split Arguments - MITRE
出向kb referenceReference - CAR-2021-05-007: CertUtil Download With VerifyCtl and Split Arguments - MITRE
出向kb referenceReference - CAR-2021-05-008: Certutil exe certificate extraction - MITRE
出向kb referenceReference - CAR-2021-05-009: CertUtil With Decode Argument - MITRE
出向kb referenceReference - CAR-2021-05-010: Create local admin accounts using net exe - MITRE
出向kb referenceReference - CAR-2013-07-005: Command Line Usage of Archiving Software - MITRE
出向kb referenceReference - CAR-2016-03-002: Create Remote Process via WMIC - MITRE
出向kb referenceReference - CAR-2019-04-004: Credential Dumping via Mimikatz - MITRE
出向kb referenceReference - CAR-2016-03-001: Host Discovery Commands - MITRE
出向kb referenceReference - CAR-2019-07-002: Lsass Process Dump via Procdump - MITRE
出向kb referenceReference - CAR-2014-04-003: Powershell Execution - MITRE
出向kb referenceReference - CAR-2014-03-006: RunDLL32.exe monitoring - MITRE
出向kb referenceReference - CAR-2019-04-003: Squiblydoo - MITRE
出向kb referenceReference - CAR-2013-07-001: Suspicious Arguments - MITRE
出向kb referenceReference - CAR-2013-05-002: Suspicious Run Locations - MITRE