Umbra Wiki defense defense/D3-PSA
Back to wiki

D3-PSA — Process Spawn Analysis

provenance: imported · ATT&CK: T1003 T1003.001 T1003.002 T1003.004 T1007 T1010 T1016 T1016.001 T1016.002 T1018 T1033 T1047 T1053 T1053.002 T1053.003 T1053.005 T1053.006 T1053.007 T1055 T1055.004 T1055.013 T1057 T1082 T1124 T1134 T1134.004 T1140 T1212 T1218 T1218.001 T1218.002 T1218.003 T1218.005 T1218.011 T1220 T1505 T1505.001 T1505.002 T1505.003 T1546 T1546.007 T1546.009 T1546.010 T1548 T1548.002 T1550 T1550.001 T1550.002 T1550.003 T1550.004 T1556 T1556.001 T1556.002 T1556.003 T1556.004 T1556.005 T1556.006 T1556.007 T1556.008 T1556.009 T1621

D3-PSA: Process Spawn Analysis

MITRE D3FEND countermeasure

What it does

Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source