Effective Parenting - detecting LRPC-based parent PID spoofing
ID: a5946172-f228-543e-a601-94e55d8c0a96
STIX ID: report--a5946172-f228-543e-a601-94e55d8c0a96
Feed Name: Elastic Security Labs
This research analyzes how adversaries evade process-tree based detections by spawning processes indirectly through RPC/LRPC mechanisms (COM, WMI, DCOM), breaking visibility into true client provenance. It examines ETW-based approaches (Microsoft-Windows-RPC events, ActivityId propagation), outlines their scalability and correlation gaps, and demonstrates that WMI Event 23’s client identity can be spoofed, making its provenance unreliable for defense. The authors recommend a generic, scalable solution—ideally a documented API exposing the client process/thread to RPC servers—to enable trustworthy correlation between LRPC calls and resultant actions and improve endpoint detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
