Parent PID Spoofing

T1134.004

Sub-technique of T1134 Access Token Manipulation.View on attack.mitre.org

About this technique

Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the CreateProcess API call, which supports a parameter that defines the PPID to use. This functionality is used by Windows features such as User Account Control (UAC) to correctly set the PPID after a requested elevated process is spawned by SYSTEM (typically via svchost.exe or consent.exe) rather than the current user context.

Adversaries may abuse these mechanisms to evade defenses, such as those blocking processes spawning directly from Office documents, and analysis targeting unusual/potentially malicious parent-child process relationships, such as spoofing the PPID of PowerShell/Rundll32 to be explorer.exe rather than an Office document delivered as part of Spearphishing Attachment. This spoofing could be executed via Visual Basic within a malicious Office document or any code that can perform Native API.

Explicitly assigning the PPID may also enable elevated privileges given appropriate access rights to the parent process. For example, an adversary in a privileged user context (i.e. administrator) may spawn a new process and assign the parent as a process running as SYSTEM (such as lsass.exe), causing the new process to be elevated via the inherited access token.

Detection rules3

Rules on DetectionCode tagged with T1134.004.

Sigma1

RuleLevelLog source
HackTool - PPID Spoofing SelectMyParent Tool Executionhighwindows / process_creation

Splunk2

RuleTypeRiskData source
Windows Parent PID Spoofing with ExplorerTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Wscript Or Cscript Suspicious Child ProcessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples4

Software4

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

MalwareDarkGate

DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer.

MalwareKONNI

KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`.

MalwarePipeMon

PipeMon can use parent PID spoofing to elevate privileges.

References5

  1. CTD PPID Spoofing Macro Mar 2019 Open source
    Tafani-Dereeper, C. (2019, March 12). Building an Office macro to spoof parent processes and command line arguments. Retrieved June 3, 2019.
  2. CounterCept PPID Spoofing Dec 2018 Open source
    Loh, I. (2018, December 21). Detecting Parent PID Spoofing. Retrieved June 3, 2019.
  3. DidierStevens SelectMyParent Nov 2009 Open source
    Stevens, D. (2009, November 22). Quickpost: SelectMyParent or Playing With the Windows Process Tree. Retrieved June 3, 2019.
  4. Microsoft UAC Nov 2018 Open source
    Montemayor, D. et al.. (2018, November 15). How User Account Control works. Retrieved June 3, 2019.
  5. XPNSec PPID Nov 2017 Open source
    Chester, A. (2017, November 20). Alternative methods of becoming SYSTEM. Retrieved June 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.