D3-PLA
enhancement
Process Lineage Analysis
Parent: D3-PA
Description
Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 14 in MITRE ATT&CK Enterprise
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1033System Owner/User Discovery
- T1053Scheduled Task/Job
- T1053.005Scheduled Task
- T1212Exploitation for Credential Access
- T1505.002Transport Agent
- T1505.003Web Shell
- T1546.007Netsh Helper DLL
- T1550Use Alternate Authentication Material
- T1556Modify Authentication Process
- T1562.001Disable or Modify Tools
- T1621Multi-Factor Authentication Request Generation
Cite as SafeMode Space, d3fend D3-PLA.