Break Process Trees
Where this stands
A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.
Both analytics describe a state/timing correlation that a single Sigma event cannot express, and every single-event proxy available in the two logsources matches the steady-state parentage of ordinary Linux and macOS processes rather than the evasive behaviour. AN1223's own wording is 're-parented to init (PID 1)' and 'parent terminates quickly after process creation' — the second clause is inherently a two-event timing comparison (lib/sigma has no timeframe/near/aggregation support per AUTHORING.md #4), and the first, expressed as a single-event proxy (ParentProcessId: 1 on the process_creation logsource, or filtering on the fork/clone/setsid syscalls on the auditd logsource), is indistinguishable from normal operation: under systemd (PID 1), every top-level service systemd starts keeps ParentProcessId=1 for its entire life as ordinary parentage, and fork/clone are called by effectively […]
Covered instead by T1027.015.
What the technique is
An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the “parent-child" relationship for detection, breaking this relationship could result in the adversary’s behavior not being associated with previous process tree activity. On Unix-based systems breaking this process tree is common practice for administrators to execute software using scripts and programs. On Linux systems, adversaries may execute a series of Native API calls to alter malware's process tree. For example, adversaries can execute their payload without any arguments, call the fork() API call twice, then have the parent process exit. This creates a grandchild process with no parent process that is immediately adopted by the init system process (PID 1), which successfully disconnects the execution of the adversary's payload from its previous process tree. Another example is using the “daemon” syscall to detach from the current parent process and run in the background.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN1223
Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis.
- AN1224
Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using daemon(), fork() or background execution flags.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.