← ./resources / blog

PPID Spoofing: Parentage Is Not Provenance

A process may report a parent chosen through supported process-creation features. Defenders should distinguish the displayed parent from the actor that initiated creation and validate both against tokens, sessions, handles, timestamps, and behavior.

Defensive scope

This guide omits process-attribute code, access-right recipes, and operational parent-selection procedures.

Three identities, not one

The reported parent, creating process, and security context can differ for legitimate reasons including brokers, launchers, deployment systems, debuggers, and sandboxes. High-quality analytics preserve these fields instead of flattening them into a single tree edge.

Preserve the complete creation relationshipActual creatorevent + handleReported parenttree relationshipNew processtoken + session + imageBehavioralconsequences
A plausible process tree can still conflict with creator and token evidence.

Detection and validation

  • Compare creator identity from endpoint or kernel telemetry with reported parent ID.
  • Find session, user, integrity, token, and timing contradictions.
  • Correlate access to the selected parent before child creation.
  • Score implausible parent-child pairs with unsigned images, unusual paths, or later injection.

Preserve creation events, process GUIDs, start times, command lines, tokens, sessions, handles, modules, and network activity. PID reuse makes timestamps essential. Use Sysmon resources, Sigma, Velociraptor, and Volatility 3. Test parsers with synthetic creation graphs.

ATT&CK and controls

PPID spoofing maps to T1134.004 Parent PID Spoofing and is normally enabled by legitimate OS functionality, not a CVE. Collect kernel-backed creator fields, retain stable process identifiers, baseline launchers and brokers, restrict debug privileges, and combine ancestry with identity and behavior.

← Previous: Fragmentation & ADSNext: Command Line Spoofing →