🎯 Goal

The objective for today was to learn how process relationships reveal malicious behavior.

Instead of looking only at individual processes, the focus was on understanding parent-child process chains, which often expose attacker activity.


πŸ›  What I Did

Studied Parent–Child Process Relationships

Every program executed on a system is launched by another process.

For example:

explorer.exe β†’ notepad.exe

This relationship forms a process tree that can be analyzed during investigations.

Learning to interpret these chains is extremely valuable in threat detection.


Identified Common Suspicious Process Chains

Several process relationships are widely associated with malicious activity.

Examples include:

winword.exe β†’ powershell.exe
excel.exe β†’ cmd.exe
chrome.exe β†’ powershell.exe

Office applications launching command shells is often linked to malicious macro execution.


Learned About Living-off-the-Land Binaries

Attackers frequently abuse legitimate system utilities known as LOLBins.

Examples include:

β€’ powershell.exe
β€’ cmd.exe
β€’ rundll32.exe
β€’ wmic.exe
β€’ mshta.exe

These tools already exist on the system, allowing attackers to execute commands without introducing obvious malware files.


πŸ”— Key Cybersecurity Connections

Parent-child process analysis is heavily used in:

β€’ endpoint detection systems
β€’ threat hunting
β€’ malware investigation

Security tools such as Sysmon record detailed process creation events, allowing analysts to observe how processes interact with each other.

Unusual process chains often provide the earliest evidence of compromise.


πŸ” Investigation Questions

When suspicious process chains appear in telemetry, investigators might ask:

  • Which parent process launched the suspicious process?
  • Is the parent-child relationship common or unusual for the environment?
  • Did the process execution include suspicious command-line arguments?
  • Did the child process establish network connections or download files?
  • Was the process executed under an unexpected user account?
  • Do similar process chains appear on multiple hosts?

These questions help analysts determine whether a process chain represents legitimate activity or malicious execution.


🚨 Detection Opportunities

Several detection opportunities exist when monitoring process relationships:

  • detecting Office applications spawning command shells
  • identifying web browsers launching scripting interpreters
  • detecting LOLBins executed by unexpected parent processes
  • monitoring suspicious command-line arguments
  • correlating process execution with network activity

Useful telemetry sources include:

  • endpoint process creation logs
  • Sysmon process events
  • EDR telemetry
  • command-line auditing logs.

🧭 MITRE ATT&CK Techniques

Suspicious process chains often relate to several MITRE ATT&CK techniques:

  • T1059 β€” Command and Scripting Interpreter
  • T1218 β€” Signed Binary Proxy Execution
  • T1204 β€” User Execution
  • T1105 β€” Ingress Tool Transfer

These techniques describe how attackers execute payloads and move through systems using legitimate processes.


⚠ Challenges

Distinguishing Normal vs Suspicious Behaviour

Some process relationships can occur during legitimate administrative tasks.

For example, system administrators may legitimately use PowerShell.

The challenge is identifying combinations that are rare or unexpected.


πŸ“š What I Learned

Process relationships reveal attacker techniques

Many attacks follow predictable execution chains.

For example:

Office document
↓
macro execution
↓
PowerShell payload
↓
network connection

Recognizing these patterns dramatically speeds up investigations.


➑ Next Steps

The next phase of learning will involve analyzing:

β€’ command-line arguments
β€’ encoded PowerShell commands
β€’ suspicious script execution

These techniques are commonly used to conceal malicious activity.


🧠 Reflection

Understanding process chains provides powerful insight into system behavior.

Instead of viewing processes in isolation, analysts can reconstruct the entire execution path of an attack.


🧩 Lessons Learned

What worked

Studying process relationships provided a clearer understanding of how attacks unfold.

What broke

Some suspicious processes may also appear during legitimate tasks.

Why it broke

Context is required to interpret system behavior accurately.

Fix / takeaway

Always evaluate process execution in combination with user, host, and command-line context.


πŸ“ˆ Skill Progression Context

The ability to interpret process chains is essential for:

β€’ endpoint detection
β€’ malware analysis
β€’ threat hunting

These skills are frequently required in SOC and incident response roles.