LiveActive security incident?Get immediate response
MITRE ATT&CK® Detection Strategy

DET0489: Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)

MITRE ATT&CK DET0489: Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows) Detection Strategy details, with detection…

EnterpriseDET0489Detection StrategyObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DET0489 is a MITRE detection strategy for behavior-chain detection of Windows Parent PID Spoofing, a technique related to stealth and privilege escalation. For leaders, the practical issue is whether endpoint and SOC processes can trust process lineage when making triage, containment, and audit decisions. If attackers can make a process appear to come from a benign parent, weak process-monitoring programs may miss suspicious execution or mis-prioritize response.

Executive priority

Prioritize this where Windows endpoint visibility, privilege escalation detection, and incident response evidence quality matter. Security leaders should ask whether the SOC can validate process ancestry beyond a simple parent-process name, whether EDR/logging retains enough process creation context for investigations, and whether detection engineering has coverage for behavior chains rather than isolated events. This supports operational resilience, compliance evidence, and response decision-making by improving confidence in endpoint execution timelines.

Technical view

The supplied object has no official description or detection text, but its relationship states it detects T1134.004 Parent PID Spoofing on Windows. SOC and detection teams should validate behavior-chain analytics around process creation where the reported parent/child relationship is unusual, inconsistent with expected execution patterns, or tied to privilege-escalation and stealth context. Triage should avoid relying only on parent process name; analysts should correlate process creation metadata, executable identity, command line, token/user context, integrity or privilege context where available, and surrounding events before escalating.

Likely telemetry

  • Windows process creation events with parent and child process identifiers
  • Process command-line and executable path metadata
  • Process user, logon session, integrity, and privilege context where collected
  • Endpoint detection and response process lineage data
  • Temporal process chain data showing what occurred before and after the suspicious process creation

Detection direction

  • Validate that process lineage analytics do not assume the reported parent process is always trustworthy.
  • Tune for behavior chains: suspicious child process creation combined with unusual ancestry, privilege context, or execution sequence is stronger than a single parent-child mismatch.
  • Baseline common administrative and software-update process chains to reduce false positives.
  • Confirm retention and normalization of process IDs, parent process IDs, timestamps, users, and command lines across endpoint tools.
  • Review blind spots where endpoint logging is disabled, command-line capture is absent, process ancestry is truncated, or EDR telemetry is unavailable during incident response.

Mitigation priorities

  • Ensure Windows endpoint logging or EDR coverage captures process creation and lineage data needed for investigation.
  • Harden privileged access and administrative workflows so unexpected privilege-context process chains stand out.
  • Use least privilege and access governance to limit the value of successful privilege-escalation attempts.
  • Operationalize detection testing for T1134.004-focused behavior chains in SOC content validation and IR tabletop scenarios.
  • Document telemetry availability and detection assumptions as compliance and audit evidence for endpoint monitoring coverage.
Additional notes and limits

This take is based on the detection strategy name, external reference DET0489, and the relationship to ATT&CK technique T1134.004 Parent PID Spoofing. The detection object itself does not provide platforms, tactics, description, or detection logic; Windows, stealth, and privilege-escalation context come from the related technique relationship.

No official detection text, analytic logic, data source list, or mitigation guidance was supplied for DET0489. Local validation is required to determine whether existing tools collect the necessary process lineage and whether analytics produce useful signal in the organization’s Windows environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1134.004Parent PID SpoofingSub-techniqueThis object detects Parent PID Spoofing.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
a44602900d3cbe2d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlea44602900d3c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackDET0489
    Open source URL
  2. [2]
    mitre-attackDET0489
    Open source URL
  3. [3]
    mitre-attackDET0489
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.