How to find anomalous process relationships in threat hunting
ID: 82b902c4-e77d-54cd-8b05-6033edd885cc
STIX ID: report--82b902c4-e77d-54cd-8b05-6033edd885cc
Feed Name: Expel Blog
### Executive summary: This article provides a five-step threat-hunting methodology for detecting anomalous parent:child process relationships—prepare (asset inventory and goals), collect process data (timestamp, process/parent names and args, host, user), narrow pairs via targeted filters, apply enrichment and analysis (Excel, scripting, reputation, file metadata), and share findings—intended to help uncover malware execution, webshells, or policy violations in enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
