D3-PSA
Process Spawn Analysis
Description
Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 36 in MITRE ATT&CK Enterprise
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1007System Service Discovery
- T1010Application Window Discovery
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1053.005Scheduled Task
- T1055.004Asynchronous Procedure Call
- T1055.013Process Doppelgänging
- T1057Process Discovery
- T1082System Information Discovery
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1140Deobfuscate/Decode Files or Information
- T1212Exploitation for Credential Access
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.003Web Shell
- T1546.007Netsh Helper DLL
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1548.002Bypass User Account Control
- T1550Use Alternate Authentication Material
- T1556Modify Authentication Process
- T1562.001Disable or Modify Tools
- T1621Multi-Factor Authentication Request Generation
Cite as SafeMode Space, d3fend D3-PSA.