logo

How to find anomalous process relationships in threat hunting

ID: 82b902c4-e77d-54cd-8b05-6033edd885cc

STIX ID: report--82b902c4-e77d-54cd-8b05-6033edd885cc

Feed Name: Expel Blog

Date Published: 2019-07-02

Date Updated: 2026-04-27

Author: Mary Singh

...
...

### Executive summary: This article provides a five-step threat-hunting methodology for detecting anomalous parent:child process relationships—prepare (asset inventory and goals), collect process data (timestamp, process/parent names and args, host, user), narrow pairs via targeted filters, apply enrichment and analysis (Excel, scripting, reputation, file metadata), and share findings—intended to help uncover malware execution, webshells, or policy violations in enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.