1200KM / simulation
T1134.004 Parent PID Spoofing — Attack Simulation
Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the CreateProcess API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features…
Technique description
Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the CreateProcess API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Parent PID Spoofing using PowerShell
Procedure 069258f4-2162-46e9-9a25-c9c6c56150d2; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Parent PID Spoofing - Spawn from Current Process
Procedure 14920ebd-1d61-491a-85e0-fe98efe37f25; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Parent PID Spoofing - Spawn from New Process
Procedure 2988133e-561c-4e42-a15f-6281e6a9b2db; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Parent PID Spoofing - Spawn from Specified Process
Procedure cbbff285-9051-444a-9d17-c07cd2d230eb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Parent PID Spoofing - Spawn from svchost.exe
Procedure e9f2b777-3123-430b-805d-5cedc66ab591; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.