Borrowed Lineage
Difficulty: medium
Topics: T1134.004 - Access Token Manipulation: Parent PID Spoofing
Problem statement
Scenario: A threat actor has successfully executed malware on a compromised workstation but faces one remaining challenge—avoiding detection by endpoint security solutions that monitor process ancestry
Instead of allowing the malicious process to reveal its true origin, the attacker attempts to manipulate how the operating system records the execution chain, making the new process appear as though it was launched by a trusted Windows application
At first glance, the process tree appears completely legitimate
Security analysts reviewing the parent-child relationship would see nothing unusual unless they inspect the process creation behavior at runtime
Traditional log-based analysis provides limited insight into how the execution chain was established, making runtime instrumentation essential for uncovering the deception
As an Endpoint Detection Engineer, your objective is to identify how the attacker manipulates process ancestry and expose the true execution chain
Objectives You must: Research Parent PID Spoofing (MITRE ATT&CK T1134.004) and understand how Windows allows applications to influence process ancestry during creation
Identify the Windows APIs involved in advanced process creation and the mechanisms used to define a process's parent
Develop API hooks to capture the runtime parameters responsible for establishing the execution chain
Analyze the collected telemetry to distinguish the spoofed parent from the actual execution context
Recover all hidden flags by observing the behavior exposed through your runtime instrumentation
Success depends on understanding how Windows constructs process relationships during process creation, rather than reverse engineering the challenge binary
The required APIs are intentionally omitted—discovering them through research is a core part of the challenge.
How to solve this challenge
Open the in-browser IDE on this page, write your solution in C or C++, and click Run. A sandboxed agent compiles your code and executes it against the target while streaming live stdout, stderr, hook traces, and verification results over a WebSocket. When your implementation succeeds, the flag is surfaced automatically.
Who is this challenge for?
Detection engineers, blue team analysts, malware researchers, security engineers, and operators who want hands-on practice with T1134.004 - Access Token Manipulation: Parent PID Spoofing.