{"id":"T1134.004","name":"Parent PID Spoofing","url":"https://attack.mitre.org/techniques/T1134/004","tactics":["stealth","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0489","stix_id":"x-mitre-detection-strategy--eb751740-80cd-4ec1-a989-8691bf7f2039","name":"Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0489","analytics":[{"id":"AN1351","stix_id":"x-mitre-analytic--312f9f86-b987-483c-8b1d-955415eea946","name":"Analytic 1351","description":"A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM.","url":"https://attack.mitre.org/detectionstrategies/DET0489#AN1351","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"api_call: UpdateProcThreadAttribute (PROC_THREAD_ATTRIBUTE_PARENT_PROCESS) and CreateProcess* with EXTENDED_STARTUPINFO_PRESENT / StartupInfoEx","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-kernel-process"},{"name":"etw:Microsoft-Windows-Kernel-Process","channel":"process_start: EventHeader.ProcessId true parent vs reported PPID mismatch","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"etw-microsoft-windows-kernel-process"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between UpdateProcThreadAttribute/CreateProcess* and the resulting process (default 5–10 minutes)."},{"field":"AllowedSpoofers","description":"Legitimate binaries that commonly use StartupInfoEx/PPID assignment (e.g., consent.exe, svchost.exe during UAC)."},{"field":"ParentPrivilegeDeltaThreshold","description":"Minimum privilege/integrity gap between chosen parent and real caller to raise severity."},{"field":"LineageMismatchTolerance","description":"Number of mismatched sources (0–3) before alerting to reduce noise."},{"field":"SensitiveParents","description":"List of SYSTEM parents that, if spoofed, auto‑escalate severity (e.g., lsass.exe, services.exe, wininit.exe)."}],"live":true,"detection_strategies":["DET0489"],"techniques":["T1134.004"]}],"live":true,"version":"1.0","techniques":["T1134.004"]}],"sigma_rules":[{"id":"52ff7941-8211-46f9-84f8-9903efb7077d","title":"HackTool - PPID Spoofing SelectMyParent Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-23","modified":"2024-11-23","description":"Detects the use of parent process ID spoofing tools like Didier Stevens tool SelectMyParent","references":["https://pentestlab.blog/2020/02/24/parent-pid-spoofing/","https://www.picussecurity.com/resource/blog/how-to-detect-parent-pid-ppid-spoofing-attacks","https://www.ired.team/offensive-security/defense-evasion/parent-process-id-ppid-spoofing","https://www.virustotal.com/gui/search/filename%253A*spoof*%2520filename%253A*ppid*/files"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1134.004"],"path":"rules/windows/process_creation/proc_creation_win_hktl_selectmyparent.yml","techniques":["T1134.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}