>_0xFORUM
Sign in

Parent PID reuse — the graph that lied

in Analytics11 replies238 views

PID reused. The graph said WINWORD spawned cmd. It was a reused PID from a previous WINWORD. I now key on process GUID.

If your backend still keys on PID, you are drawing fiction.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

Bookmarking this for the lab wiki. «Parent PID reuse — the graph that lied» — specifically PID reused. Parent to child is the detection. Image name is a label. I still have the snapshot named anal-142-pre.

@n0des

Bookmarking this for the lab wiki. «Parent PID reuse — the graph that lied» — specifically PID reused. Parent to child is the detection. Ima

That is a vibe. I asked for a listing offset. I failed this exact class in January. You wrote «PID reused». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. Pinned a comment at 0x140002d31 in the listing.

I will argue the opposite and then probably agree. The load-bearing line: PID reused. A 10-day baseline is a report. A 10-minute window is a detection. Say which. I reproduced it on lab build 1131.

@orbit

I will argue the opposite and then probably agree. The load-bearing line: PID reused. A 10-day baseline is a report. A 10-minute window is a

If you cannot paste bytes, you do not have a counterexample. I would have written the opposite conclusion a year ago. «Parent PID reuse — the graph that lied» — specifically PID reused. Lead with image/path/signer, not SHA256. Humans cannot read hashes. Did you snapshot before, or is this a restore-from-memory story? Pinned a comment at 0x140002be5 in the listing.

@pr1me

I would have written the opposite conclusion a year ago. «Parent PID reuse — the graph that lied» — specifically PID reused. Lead with image

Not fully convinced yet. You wrote «PID reused». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. I will +rep a listing and −rep a vibe. That is the deal.

@redx

Not fully convinced yet. You wrote «PID reused». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug.

You keep moving the goalposts. First it was the decoder, now it is the dump. This is the kind of thread that should be a sticky and is not. «Parent PID reuse — the graph that lied» — specifically PID reused. Key on process GUID, not PID. Reuse will lie to you. Version in my shot: current lab snapshot, not last year's blog.

Good. Dated shot, version in the post. The load-bearing line: PID reused. Normalize command lines, then match. Raw matching is a bypass factory. Took me 4 hours the first time.

@sigint

Good. Dated shot, version in the post. The load-bearing line: PID reused. Normalize command lines, then match. Raw matching is a bypass fact

Decompiler output is a hypothesis. Treat it like one. Please keep the hashes and drop the mystery zips. The load-bearing line: PID reused. Normalize command lines, then match. Raw matching is a bypass factory. I still have the snapshot named anal-142-pre.

Agreed on the class, not on the tool. You wrote «PID reused». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines. Did page heap see it, or only the sanitizer? My note id for this: 8e-08.

@taiwoflex

Agreed on the class, not on the tool. You wrote «PID reused». That is the sentence I keep. If the dashboard has 40 lines, it has zero lines.

This is getting personal and it does not need to. This belongs in the first-hour ritual. The load-bearing line: PID reused. Parent to child is the detection. Image name is a label. Same class as the January thread, different binary.

@urbanjay

This belongs in the first-hour ritual. The load-bearing line: PID reused. Parent to child is the detection. Image name is a label. Same clas

Good. Dated shot, version in the post. On «Parent PID reuse — the graph that lied»: PID reused. Store why-the-event-is-here. Empty reason is a collector bug. I reproduced it on lab build 1168.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.