← ./resources / blog

Process Ghosting: Correlating Objects Across Time

Process ghosting abuses a timing gap between file disposition, executable section creation, and process initialization. It challenges path-centric monitoring, but it does not erase kernel objects, memory mappings, process ancestry, identity, or post-start behavior.

Defensive scope

This analysis stays at the architectural and detection level. It excludes API sequences, source code, and steps for producing a ghosted process.

Why the timeline matters

Traditional controls expect an executable path to remain available when a process is inspected. In ghosting research, content associated with a delete-pending file can contribute to an executable section before process initialization completes. Later path lookup may fail or describe an object whose on-disk lifecycle no longer matches the mapped image. The durable unit of analysis is therefore the event chain, not the final pathname.

Correlate the full creation timelineFile contentwrittenDelete-pendingstateExecutablesectionProcessinitializedMemory + behaviorvalidatedJoin on process ID, creator, file ID, volume, section, timestamps, image hash, token, and destination
Each event may look ordinary alone; the ordering and object relationships make the chain unusual.

Detection opportunities

  • Executable content written by a rare or unsigned process and quickly marked for deletion.
  • Image section or process creation whose backing file cannot be reopened or validated.
  • Mismatch among reported image path, process parameters, mapped image bytes, and signer.
  • Process creation without the expected preceding file and image-validation telemetry.
  • Suspicious child behavior, token use, or networking immediately after initialization.

Kernel and EDR telemetry should be retained alongside Sysmon and filesystem evidence. User-mode process-start events alone may arrive too late to explain the earlier object transitions.

Forensic workflow and tools

Capture memory before termination when safe, preserve the process tree, and collect NTFS metadata. Compare the main image mapping against any available file, inspect the PEB image path and process parameters as untrusted clues, validate the token, and reconstruct the file lifecycle. Velociraptor, MFTECmd, Volatility 3, and PE-sieve support collection and analysis.

Safe validation

Test correlation logic with benign temporary files and normal process launches as separate controls; do not reproduce the technique. Simulate the expected event fields in a SIEM test index, verify ordering and joins, then replay known-good installer and updater telemetry to measure false positives.

ATT&CK, CVEs, and mitigation

Process ghosting fits T1055 Process Injection and may overlap T1036 Masquerading or T1070.004 File Deletion. It describes use of legitimate object semantics, not a standalone Windows CVE. Prioritize current Windows updates, application control, least privilege, endpoint sensors with early process telemetry, and detections that correlate file disposition to section and process events.

← Previous: Ghost FilesNext: Pool Party →