Skip to content

Support for FAA policies that check process parent / ancestry #789

@craigjbass

Description

@craigjbass

Summary

Distinguish legitimate threat hunting activity from living off the land attacks

Description

Microsoft Defender allows system administrators / threat hunting teams to execute e.g. system python scripts to gather intelligence from devices. These scripts have a parent of wdavdaemon_enterprise which is code signed.

We'd like to be able to configure a policy to allow python to execute in this manner if it is owned by wdavdaemon_enterprise.

Suggestion is to allow FAA policies that support matching rules on https://developer.apple.com/documentation/endpointsecurity/es_process_t/parent_audit_token

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request
    No fields configured for Feature.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions