Command-Line Spoofing: Capture Intent Before the Story Changes
A process command line may be observed at creation, read later from process state, reconstructed by a sensor, or logged by the application. Those views can disagree. Defenders need source-aware telemetry and downstream behavior to determine which account is credible.
No process-parameter mutation code, memory offsets, or recipes for misleading sensors are included.
Command lines have provenance
Creation-time arguments are often the strongest view of initial intent, while later process memory reflects mutable state. Truncation, quoting, encoding, redaction, wrappers, and parser differences can also create benign disagreement. Store the raw value, normalized value, capture time, source, and truncation status.
Detection and investigation
- Compare creation-time command lines with later memory and application records.
- Correlate claimed arguments with actual files, network endpoints, children, and loaded modules.
- Flag implausibly benign or empty arguments before high-risk behavior.
- Distinguish mutation from truncation, redaction, quoting, and encoding differences.
Preserve raw creation events, stable process IDs, process parameters, environment, image hashes, lineage, tokens, and downstream activity. Use Sigma, Velociraptor, Volatility 3, and Hayabusa. Safely test normalization with synthetic records containing quoting, Unicode, truncation, and intentional source conflicts.
ATT&CK and controls
This behavior can support T1036 Masquerading or T1562.001 Impair Defenses and is not inherently a CVE. Capture command lines at creation from protected telemetry, document parser semantics, preserve originals before normalization, control sensitive log access, and detect effects even when arguments are absent.