Anti-Forensics
Account Misuse
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF037
- Created: 22nd July 2026
- Updated: 22nd July 2026
- Platforms: MacOSWindowsLinux
- MITRE ATT&CK®: T1134.004
- Contributor: The ITM Team
Parent Process ID Spoofing
The subject causes a newly created process to record or present a false parent process identifier, obscuring the process responsible for initiating the activity. This creates a misleading parent-child relationship within process trees and may cause unauthorized execution to appear as though it originated from a trusted, routine, or unrelated process. This Section concerns the deliberate falsification of process ancestry to evade monitoring, conceal the origin of execution, or frustrate subsequent investigation.
Parent process ID spoofing can undermine detections based on expected process lineage and complicate forensic reconstruction of the execution chain. The subject may use process-creation application programming interfaces or specialist tooling to assign an alternate parent process when launching code.
Preventions (3)
Detections (5)
MITRE ATT&CK® Mapping (1)
ATT&CK Enterprise Matrix Version 19.1