ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships

August 2020 Bobby Filar, David French arXiv preprint

We present ProblemChild, a framework for surfacing anomalous parent-child process relationships from endpoint telemetry — a useful signal for catching living-off-the-land and post-exploit behaviors that single-process detection rules miss.

arXiv:2008.04676