π Day 43 β Detecting Suspicious Process Chains
π― Goal
The objective for today was to learn how process relationships reveal malicious behavior.
Instead of looking only at individual processes, the focus was on understanding parent-child process chains, which often expose attacker activity.
π What I Did
Studied ParentβChild Process Relationships
Every program executed on a system is launched by another process.
For example:
explorer.exe β notepad.exe
This relationship forms a process tree that can be analyzed during investigations.
Learning to interpret these chains is extremely valuable in threat detection.
Identified Common Suspicious Process Chains
Several process relationships are widely associated with malicious activity.
Examples include:
winword.exe β powershell.exe
excel.exe β cmd.exe
chrome.exe β powershell.exe
Office applications launching command shells is often linked to malicious macro execution.
Learned About Living-off-the-Land Binaries
Attackers frequently abuse legitimate system utilities known as LOLBins.
Examples include:
β’ powershell.exe
β’ cmd.exe
β’ rundll32.exe
β’ wmic.exe
β’ mshta.exe
These tools already exist on the system, allowing attackers to execute commands without introducing obvious malware files.
π Key Cybersecurity Connections
Parent-child process analysis is heavily used in:
β’ endpoint detection systems
β’ threat hunting
β’ malware investigation
Security tools such as Sysmon record detailed process creation events, allowing analysts to observe how processes interact with each other.
Unusual process chains often provide the earliest evidence of compromise.
π Investigation Questions
When suspicious process chains appear in telemetry, investigators might ask:
- Which parent process launched the suspicious process?
- Is the parent-child relationship common or unusual for the environment?
- Did the process execution include suspicious command-line arguments?
- Did the child process establish network connections or download files?
- Was the process executed under an unexpected user account?
- Do similar process chains appear on multiple hosts?
These questions help analysts determine whether a process chain represents legitimate activity or malicious execution.
π¨ Detection Opportunities
Several detection opportunities exist when monitoring process relationships:
- detecting Office applications spawning command shells
- identifying web browsers launching scripting interpreters
- detecting LOLBins executed by unexpected parent processes
- monitoring suspicious command-line arguments
- correlating process execution with network activity
Useful telemetry sources include:
- endpoint process creation logs
- Sysmon process events
- EDR telemetry
- command-line auditing logs.
π§ MITRE ATT&CK Techniques
Suspicious process chains often relate to several MITRE ATT&CK techniques:
- T1059 β Command and Scripting Interpreter
- T1218 β Signed Binary Proxy Execution
- T1204 β User Execution
- T1105 β Ingress Tool Transfer
These techniques describe how attackers execute payloads and move through systems using legitimate processes.
β Challenges
Distinguishing Normal vs Suspicious Behaviour
Some process relationships can occur during legitimate administrative tasks.
For example, system administrators may legitimately use PowerShell.
The challenge is identifying combinations that are rare or unexpected.
π What I Learned
Process relationships reveal attacker techniques
Many attacks follow predictable execution chains.
For example:
Office document
β
macro execution
β
PowerShell payload
β
network connection
Recognizing these patterns dramatically speeds up investigations.
β‘ Next Steps
The next phase of learning will involve analyzing:
β’ command-line arguments
β’ encoded PowerShell commands
β’ suspicious script execution
These techniques are commonly used to conceal malicious activity.
π§ Reflection
Understanding process chains provides powerful insight into system behavior.
Instead of viewing processes in isolation, analysts can reconstruct the entire execution path of an attack.
π§© Lessons Learned
What worked
Studying process relationships provided a clearer understanding of how attacks unfold.
What broke
Some suspicious processes may also appear during legitimate tasks.
Why it broke
Context is required to interpret system behavior accurately.
Fix / takeaway
Always evaluate process execution in combination with user, host, and command-line context.
π Skill Progression Context
The ability to interpret process chains is essential for:
β’ endpoint detection
β’ malware analysis
β’ threat hunting
These skills are frequently required in SOC and incident response roles.
