Umbra Wiki defense defense/D3-PLA
Back to wiki

D3-PLA — Process Lineage Analysis

provenance: imported · ATT&CK: T1003 T1003.001 T1003.002 T1003.004 T1033 T1053 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1212 T1505 T1505.002 T1505.003 T1546 T1546.007 T1550 T1550.001 T1550.002 T1550.003 T1550.004 T1556 T1556.001 T1556.002 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.008 T1556.009 T1621

D3-PLA: Process Lineage Analysis

MITRE D3FEND countermeasure

What it does

Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source