DET0489: Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
MITRE ATT&CK DET0489: Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows) Detection Strategy details, with detection…
Security context for executives and security teams
DET0489 is a MITRE detection strategy for behavior-chain detection of Windows Parent PID Spoofing, a technique related to stealth and privilege escalation. For leaders, the practical issue is whether endpoint and SOC processes can trust process lineage when making triage, containment, and audit decisions. If attackers can make a process appear to come from a benign parent, weak process-monitoring programs may miss suspicious execution or mis-prioritize response.
Executive priority
Prioritize this where Windows endpoint visibility, privilege escalation detection, and incident response evidence quality matter. Security leaders should ask whether the SOC can validate process ancestry beyond a simple parent-process name, whether EDR/logging retains enough process creation context for investigations, and whether detection engineering has coverage for behavior chains rather than isolated events. This supports operational resilience, compliance evidence, and response decision-making by improving confidence in endpoint execution timelines.
Technical view
The supplied object has no official description or detection text, but its relationship states it detects T1134.004 Parent PID Spoofing on Windows. SOC and detection teams should validate behavior-chain analytics around process creation where the reported parent/child relationship is unusual, inconsistent with expected execution patterns, or tied to privilege-escalation and stealth context. Triage should avoid relying only on parent process name; analysts should correlate process creation metadata, executable identity, command line, token/user context, integrity or privilege context where available, and surrounding events before escalating.
Likely telemetry
- Windows process creation events with parent and child process identifiers
- Process command-line and executable path metadata
- Process user, logon session, integrity, and privilege context where collected
- Endpoint detection and response process lineage data
- Temporal process chain data showing what occurred before and after the suspicious process creation
Detection direction
- Validate that process lineage analytics do not assume the reported parent process is always trustworthy.
- Tune for behavior chains: suspicious child process creation combined with unusual ancestry, privilege context, or execution sequence is stronger than a single parent-child mismatch.
- Baseline common administrative and software-update process chains to reduce false positives.
- Confirm retention and normalization of process IDs, parent process IDs, timestamps, users, and command lines across endpoint tools.
- Review blind spots where endpoint logging is disabled, command-line capture is absent, process ancestry is truncated, or EDR telemetry is unavailable during incident response.
Mitigation priorities
- Ensure Windows endpoint logging or EDR coverage captures process creation and lineage data needed for investigation.
- Harden privileged access and administrative workflows so unexpected privilege-context process chains stand out.
- Use least privilege and access governance to limit the value of successful privilege-escalation attempts.
- Operationalize detection testing for T1134.004-focused behavior chains in SOC content validation and IR tabletop scenarios.
- Document telemetry availability and detection assumptions as compliance and audit evidence for endpoint monitoring coverage.
Additional notes and limits
This take is based on the detection strategy name, external reference DET0489, and the relationship to ATT&CK technique T1134.004 Parent PID Spoofing. The detection object itself does not provide platforms, tactics, description, or detection logic; Windows, stealth, and privilege-escalation context come from the related technique relationship.
No official detection text, analytic logic, data source list, or mitigation guidance was supplied for DET0489. Local validation is required to determine whether existing tools collect the necessary process lineage and whether analytics produce useful signal in the organization’s Windows environment.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1134.004 | Parent PID SpoofingSub-technique | This object detects Parent PID Spoofing. |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | a44602900d3c… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]mitre-attackDET0489Open source URL
- [2]mitre-attackDET0489Open source URL
- [3]mitre-attackDET0489Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
