Compliance Node Overview
MITRE ATT&CK T1134.004 (Parent PID Spoofing) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are typically spawned directly from their parent, or calling, process unless explicitly specified. One way of explicitly assigning the PPID of a new process is via the CreateProcess API call, which supports a parameter that defines the PPID to use. Affected platforms: Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-05, CM-06, IA-02, IA-13.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1134/004/
SHA-256 integrity: 3fb369f7b35176ffcc126d941f1ed16e43be638db2cd4d245a616f6fc35d3b69
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1134.004: Parent PID Spoofing (https://attack.mitre.org/techniques/T1134/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.