>_0xFORUM
Sign in

Graphing process ancestry from ETW without drowning

in Analytics41 replies7k views

If you ingest every ProcessStart you will drown. Filter: parent in a denylist OR child unsigned OR spawned from Office/browser.

Then a 20-line graph (parent_guid -> child_guid) in sqlite. Detections become 'path exists from WINWORD to powershell with NetworkConnect'. Boring, reliable.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 41 REPLIES

I want the listing, not the decompiler story. The load-bearing line: If you ingest every ProcessStart you will drown. Parent to child is the detection. Image name is a label. Same class as the June thread, different binary.

@grayhat

I want the listing, not the decompiler story. The load-bearing line: If you ingest every ProcessStart you will drown. Parent to child is the

Decompiler output is a hypothesis. Treat it like one. I want the listing, not the decompiler story. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Join on PID plus create-time plus image when clocks disagree. Took me 6 hours the first time.

@hyper

I tried the naive path first and wasted a morning. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every

This is getting personal and it does not need to. I will argue the opposite and then probably agree. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. Did you force-create the function or did auto-analysis luck into it? My note id for this: 88-03.

I would have written the opposite conclusion a year ago. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. Pinned a comment at 0x14000002e in the listing.

I tried the naive path first and wasted a morning. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. I still have the snapshot named anal-136-pre.

@intelr

I will argue the opposite and then probably agree. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every

The screenshot is the useful part of the post. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Version in my shot: current lab snapshot, not last year's blog.

@k3rnl

The screenshot is the useful part of the post. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image/path/

That insult was not a technical point. I am reporting it. If you only have the decompiler, you do not have the bug. The load-bearing line: If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. My note id for this: 88-05.

@dump_the_core

The screenshot is the useful part of the post. The load-bearing line: If you ingest every ProcessStart you will drown. A 10-day baseline is

Decompiler output is a hypothesis. Treat it like one. Agreed on the class, not on the tool. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Normalize command lines, then match. Raw matching is a bypass factory. Version in my shot: current lab snapshot, not last year's blog.

Please keep the hashes and drop the mystery zips. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Took me 2 hours the first time.

@eliashub

Please keep the hashes and drop the mystery zips. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep.

Stop flexing an IDA license. The question was the unwind info. Came back to this after a coffee. Still hold. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. Same class as the March thread, different binary.

@lima

I would have written the opposite conclusion a year ago. «Graphing process ancestry from ETW without drowning» — specifically If you ingest

I am reporting the sample-drop hint. Hash and corpus tag only. I want the listing, not the decompiler story. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. If anyone DMs me a zip I will not open it. Hash in-thread.

I dumped after OEP and then did this. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. Same class as the January thread, different binary.

@buffr

I dumped after OEP and then did this. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashb

That insult was not a technical point. I am reporting it. This matches a public n-day class from last patch Tuesday. The load-bearing line: If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. Took me 10 hours the first time.

@cldsec

I failed this exact class in January. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart

I am reporting the sample-drop hint. Hash and corpus tag only. I still keep a paper notebook for this kind of note. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. Normalize command lines, then match. Raw matching is a bypass factory. I reproduced it on lab build 1264.

I failed this exact class in January. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA256. Humans cannot read hashes. My note id for this: 88-26.

@axi0m

Not fully convinced yet. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. If the d

This is getting personal and it does not need to. I want the listing, not the decompiler story. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Rare-on-Tuesday is patch Tuesday. Exclude the window. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@liveconnect

I still keep a paper notebook for this kind of note. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image

This is the kind of thread that should be a sticky and is not. The load-bearing line: If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. I wrote a 12-line script and then threw it away. The listing was enough.

The screenshot is the useful part of the post. The load-bearing line: If you ingest every ProcessStart you will drown. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I will +rep a listing and −rep a vibe. That is the deal.

Also: Rare-on-Tuesday is patch Tuesday. Exclude the window.

@analyst

Agreed on the class, not on the tool. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart

Not fully convinced yet. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. If the dashboard has 40 lines, it has zero lines. Same class as the January thread, different binary.

@freq

I ran this on a licensed corpus binary. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStar

Calling the sticky 'priest talk' is how you earn a ban note. Quietly the best note on this board this month. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. Key on process GUID, not PID. Reuse will lie to you. What did you key the join on — PID or process GUID? My note id for this: 88-33.

@grayx

Quietly the best note on this board this month. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart y

I failed this exact class in January. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. Took me 6 hours the first time.

@hassanwise

I failed this exact class in January. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will dr

That is a vibe. I asked for a listing offset. I reproduced it twice before I believed you. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. Same class as the January thread, different binary.

@l0gic

I tried the naive path first and wasted a morning. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every

You keep moving the goalposts. First it was the decoder, now it is the dump. I still keep a paper notebook for this kind of note. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA256. Humans cannot read hashes. I reproduced it on lab build 1173.

I ran this on a licensed corpus binary. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. If anyone DMs me a zip I will not open it. Hash in-thread.

@crypt

I still keep a paper notebook for this kind of note. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessSt

Same wall I hit last quarter. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@danielrocks

Same wall I hit last quarter. The load-bearing line: If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA25

The graph hid it. The listing did not. Trust the listing. This is the writeup I wanted when I was stuck. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. I will +rep a listing and −rep a vibe. That is the deal.

I want the listing, not the decompiler story. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Lead with image/path/signer, not SHA256. Humans cannot read hashes. If anyone DMs me a zip I will not open it. Hash in-thread.

Also: If the dashboard has 40 lines, it has zero lines.

@intelx

I want the listing, not the decompiler story. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every Proce

If you cannot paste bytes, you do not have a counterexample. I reproduced it twice before I believed you. The load-bearing line: If you ingest every ProcessStart you will drown. First-seen is first-seen-by-us. Name the column that way. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Did page heap see it, or only the sanitizer? Took me 11 hours the first time.

This matches a public n-day class from last patch Tuesday. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. Did page heap see it, or only the sanitizer? Same class as the January thread, different binary.

@netmap

This matches a public n-day class from last patch Tuesday. You wrote «If you ingest every ProcessStart you will drown». That is the sentence

The graph hid it. The listing did not. Trust the listing. Agreed on the class, not on the tool. The load-bearing line: If you ingest every ProcessStart you will drown. Normalize command lines, then match. Raw matching is a bypass factory. Same class as the March thread, different binary.

@ohmx

Agreed on the class, not on the tool. The load-bearing line: If you ingest every ProcessStart you will drown. Normalize command lines, then

I still keep a paper notebook for this kind of note. The load-bearing line: If you ingest every ProcessStart you will drown. Rare-on-Tuesday is patch Tuesday. Exclude the window. I wrote a 12-line script and then threw it away. The listing was enough.

@osint

I still keep a paper notebook for this kind of note. The load-bearing line: If you ingest every ProcessStart you will drown. Rare-on-Tuesday

Stop flexing an IDA license. The question was the unwind info. Same wall I hit last quarter. The load-bearing line: If you ingest every ProcessStart you will drown. If the dashboard has 40 lines, it has zero lines. I still have the snapshot named anal-136-pre.

I failed this exact class in January. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. I still have the snapshot named anal-136-pre.

Also: First-seen is first-seen-by-us. Name the column that way.

@rfsec

I failed this exact class in January. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashb

Calling the sticky 'priest talk' is how you earn a ban note. I dumped after OEP and then did this. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Rare-on-Tuesday is patch Tuesday. Exclude the window. Did page heap see it, or only the sanitizer? I reproduced it on lab build 1351.

I want the listing, not the decompiler story. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. Parent to child is the detection. Image name is a label. I reproduced it on lab build 1200.

@sigx

I want the listing, not the decompiler story. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you

That is a vibe. I asked for a listing offset. Same wall I hit last quarter. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. If the dashboard has 40 lines, it has zero lines. I will +rep a listing and −rep a vibe. That is the deal.

@stackr

Same wall I hit last quarter. On «Graphing process ancestry from ETW without drowning»: If you ingest every ProcessStart you will drown. If

I dumped after OEP and then did this. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Parent to child is the detection. Image name is a label. I reproduced it on lab build 1107.

@thet4

I dumped after OEP and then did this. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Parent to ch

If you cannot paste bytes, you do not have a counterexample. Good. Dated shot, version in the post. «Graphing process ancestry from ETW without drowning» — specifically If you ingest every ProcessStart you will drown. Join on PID plus create-time plus image when clocks disagree. My note id for this: 88-17.

I still keep a paper notebook for this kind of note. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. Key on process GUID, not PID. Reuse will lie to you. Which build of the tool? I got burned mixing notes across versions. I will +rep a listing and −rep a vibe. That is the deal.

@warden

I still keep a paper notebook for this kind of note. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I kee

You keep moving the goalposts. First it was the decoder, now it is the dump. This belongs in the first-hour ritual. You wrote «If you ingest every ProcessStart you will drown». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.