{"id":"T1036.009","name":"Break Process Trees","url":"https://attack.mitre.org/techniques/T1036/009","tactics":["stealth"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0443","stix_id":"x-mitre-detection-strategy--eccdd5b4-e19e-4254-909e-4a9c2e3ac27e","name":"Detection Strategy for Masquerading via Breaking Process Trees","url":"https://attack.mitre.org/detectionstrategies/DET0443","analytics":[{"id":"AN1223","stix_id":"x-mitre-analytic--d4a29d94-bce4-4069-a0b5-9e0e731cff97","name":"Analytic 1223","description":"Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis.","url":"https://attack.mitre.org/detectionstrategies/DET0443#AN1223","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"fork/clone/daemon syscall tracing","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve of re-parented process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TimeWindow","description":"Maximum time between parent and child process creation and parent process termination"},{"field":"ReparentingDetectionScope","description":"Scope for detecting unexpected re-parenting to init/systemd"},{"field":"ExecutableScope","description":"Subset of monitored executables or services likely to abuse double-fork"}],"live":true,"detection_strategies":["DET0443"],"techniques":["T1036.009"]},{"id":"AN1224","stix_id":"x-mitre-analytic--269ab5e4-4c45-4f7a-8d82-c235492ff83a","name":"Analytic 1224","description":"Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using `daemon()`, `fork()` or background execution flags.","url":"https://attack.mitre.org/detectionstrategies/DET0443#AN1224","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process creation with parent PID of 1 (launchd)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"Detached process execution with no associated parent","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"AnomalyParentPID","description":"Triggering PID used to flag abnormal child adoption (commonly PID 1)"},{"field":"AllowedServices","description":"Allowlist of background daemons legitimately using launchd as parent"},{"field":"ProcessNameEntropy","description":"Entropy score threshold for abnormal process names in detached state"}],"live":true,"detection_strategies":["DET0443"],"techniques":["T1036.009"]}],"live":true,"version":"1.0","techniques":["T1036.009"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}