← ./resources / blog

Command-Line Spoofing: Capture Intent Before the Story Changes

A process command line may be observed at creation, read later from process state, reconstructed by a sensor, or logged by the application. Those views can disagree. Defenders need source-aware telemetry and downstream behavior to determine which account is credible.

Defensive scope

No process-parameter mutation code, memory offsets, or recipes for misleading sensors are included.

Command lines have provenance

Creation-time arguments are often the strongest view of initial intent, while later process memory reflects mutable state. Truncation, quoting, encoding, redaction, wrappers, and parser differences can also create benign disagreement. Store the raw value, normalized value, capture time, source, and truncation status.

Compare source-aware views over time Creation event initial arguments Process memory later state Application logs parsed intent Observed files, network, children Record source · timestamp · raw value · normalization · truncation
Disagreement is useful only when investigators know when and where each value was captured.

Detection and investigation

  • Compare creation-time command lines with later memory and application records.
  • Correlate claimed arguments with actual files, network endpoints, children, and loaded modules.
  • Flag implausibly benign or empty arguments before high-risk behavior.
  • Distinguish mutation from truncation, redaction, quoting, and encoding differences.

Preserve raw creation events, stable process IDs, process parameters, environment, image hashes, lineage, tokens, and downstream activity. Use Sigma, Velociraptor, Volatility 3, and Hayabusa. Safely test normalization with synthetic records containing quoting, Unicode, truncation, and intentional source conflicts.

ATT&CK and controls

This behavior can support T1036 Masquerading or T1562.001 Impair Defenses and is not inherently a CVE. Capture command lines at creation from protected telemetry, document parser semantics, preserve originals before normalization, control sensitive log access, and detect effects even when arguments are absent.

← Previous: PPID SpoofingNext: Intent-Aware Security →