Attack Ent T1134 004 Parent Pid Spoofing

Analyze MITRE ATT&CK T1134.004 Parent PID Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134.004, Parent PID Spoofing, or enterprise ATT&CK. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.

santosomar Updated

File contents

santosomar/mitre-attack-agent-skills/tree/main/enterprise/attack-ent-t1134-004-parent-pid-spoofing commit 5017bdea40

Frequently asked questions

npx skillmds@latest add santosomar/attack-ent-t1134-004-parent-pid-spoofing