Refers to the event in which a new process (executable) is initialized by an operating system. This can involve parent-child process relationships, process arguments, and environmental variables. Monitoring process creation is crucial for detecting malicious behaviors, such as execution of unauthorized binaries, scripting abuse, or privilege escalation attempts..
ID: DC0032
Domains: ICS, Mobile, Enterprise
Version: 2.1
Created: 20 October 2021
Last Modified: 12 May 2026
Log Sources
Name
Channel
android:logcat
dlopen of a recently created .so OR short-lived child (/system/bin/sh,toybox,linker) spawned by app_process
android:logcat
startActivity on top of (launchMode/singleTop), task switch immediately after focus
android:logcat
unexpected spikes in fork/exec/app process start events for helper utilities used for enumeration (ps, toybox/toolbox variants) from same UID
AndroidLogs:Framework
Creation of a new process running as system or root UID whose executable path resides under an app container path (for example, /data/app or /data/user/0/), or whose parent process originates from an app sandbox
AndroidLogs:Kernel
init or zygote process executing scripts or binaries from non-standard data or sdcard locations during early boot
auditd:EXECVE
execve: Processes launched with LD_PRELOAD/LD_LIBRARY_PATH pointing to non-system dirs
auditd:EXECVE
EXECVE
auditd:EXECVE
execution of unexpected binaries during user shell startup
auditd:EXECVE
systemctl spawning managed processes
auditd:EXECVE
execve
auditd:EXECVE
Execution of dd, shred, wipe targeting block devices
Shell commands invoked by SQL process such as postgres, mysqld, or mariadbd
auditd:EXECVE
Execution of ssh/scp/sftp without corresponding authentication log
auditd:EXECVE
Execution of dd/sgdisk with arguments writing to sector 0 or partition table
auditd:EXECVE
Execution of dd, shred, or wipe with arguments targeting block devices
auditd:EXECVE
systemctl stop auditd, kill -9 , or modifications to /etc/selinux/config
auditd:EXECVE
cat|less|grep accessing .bash_history from a non-shell process
auditd:EXECVE
Process execution via .desktop Exec path from /etc/xdg/autostart or ~/.config/autostart
auditd:SYSCALL
execve
auditd:SYSCALL
execve network tools
auditd:SYSCALL
execve calls to soffice.bin with suspicious macro execution flags
auditd:SYSCALL
execve of systemctl or service stop
auditd:SYSCALL
execve of launchctl or pkill
auditd:SYSCALL
execve: Execution of klist, kinit, or tools interacting with ccache outside normal user context
auditd:SYSCALL
execve: Electron-based binary spawning shell or script interpreter
auditd:SYSCALL
execve calls with high-frequency or known bandwidth-intensive tools
auditd:SYSCALL
execve or syscall invoking vm artifact check commands (e.g., dmidecode, lspci, dmesg)
auditd:SYSCALL
process persists beyond parent shell termination
auditd:SYSCALL
execve: Execution of scripts or binaries sourced from mail directories (/var/mail, ~/Maildir)
auditd:SYSCALL
execve: Execution of container management CLIs (docker, crictl, kubectl) or interpreted shells (sh, bash, python) within container context
auditd:SYSCALL
execve: Execution of discovery commands targeting backup binaries, processes, or config paths
auditd:SYSCALL
execve: Execution of scripts or binaries spawned from browser processes
auditd:SYSCALL
EXECVE
auditd:SYSCALL
execve: Execution of bash, python, or perl processes spawned by browser/email client
auditd:SYSCALL
execve of /bin/sh,/bin/bash,/usr/bin/curl,/usr/bin/python by service accounts (e.g., apache, mysql, nobody) immediately after inbound network activity.
auditd:SYSCALL
SYSCALL record where exe contains passwd/userdel/chage and auid != root
auditd:SYSCALL
execve of base64|openssl|xxd|python|perl with arguments matching Base64 flags
auditd:SYSCALL
execve on code or jetbrains-gateway with remote flags
auditd:SYSCALL
execve of sleep or ping command within script interpreted by bash/python
auditd:SYSCALL
execve or socket/connect system calls from processes using crypto libraries
auditd:SYSCALL
type=EXECVE or SYSCALL for /bin/date, /usr/bin/timedatectl, /sbin/hwclock, /bin/cat /etc/timezone, /bin/cat /proc/uptime
execution of known flash tools (e.g., flashrom, fwupd)
auditd:SYSCALL
execve of system tools like dmidecode, lspci, lscpu, dmesg, systemd-detect-virt
auditd:SYSCALL
execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login)
auditd:SYSCALL
execve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget)
auditd:SYSCALL
execve of smbclient, smbmap, rpcclient, nmblookup, crackmapexec smb
auditd:SYSCALL
execve call with argv matching known disk enumeration commands (lsblk, parted, fdisk)
auditd:SYSCALL
execve, connect
auditd:SYSCALL
execve logging for /usr/bin/systemctl and systemd-run
auditd:SYSCALL
execve: Execution of files saved in mail or download directories
auditd:SYSCALL
execve: Execution of CLI tools like psql, mysql, mongo, sqlite3
auditd:SYSCALL
execve: Execution of pip, npm, gem, or similar package managers
auditd:SYSCALL
fork/exec of service via PID 1 (systemd)
auditd:SYSCALL
execve: execve where exe=/usr/bin/python3 or similar interpreter
auditd:SYSCALL
Execution of binaries located in /etc/init.d/ or systemd service paths
auditd:SYSCALL
execve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser
auditd:SYSCALL
execve: Commands that alter firewall or start listeners: iptables|nft|ufw|firewall-cmd|pfctl|systemctl start sshd/telnet/dropbear; raw-socket/libpcap tools (tcpdump, tshark, nmap --raw).
auditd:SYSCALL
execve: Execution of binaries/scripts presenting false health messages for security daemons
auditd:SYSCALL
execve, setifflags
auditd:SYSCALL
execve calls for qemu-system*, kvm, or VBoxHeadless
auditd:SYSCALL
execve of interpreters (python, perl), custom binaries, or shell utilities with long arguments containing non-standard tokens
auditd:SYSCALL
Execution of dpkg or rpm followed by fork/execve from within postinst, prerm, etc.
auditd:SYSCALL
execve: exe in (/usr/bin/bash,/usr/bin/sh,/usr/bin/zsh,/usr/bin/python*) AND cmdline matches '(curl|wget).*(\||\|\s*sh|bash)|base64\s*-d|python\s*-c'
auditd:SYSCALL
Invocation of packet generation tools (e.g., hping3, nping) or fork bombs
auditd:SYSCALL
execve for proxy tools
auditd:SYSCALL
execve or nanosleep with no stdout/stderr I/O
auditd:SYSCALL
Execution of dpkg, rpm, or other package manager with list flag
auditd:SYSCALL
apache2 or nginx spawning sh, bash, or python interpreter
auditd:SYSCALL
execve: Execution of commands modifying iptables/nftables to block selective IPs
auditd:SYSCALL
execve with LD_PRELOAD or linker-related environment variables set
auditd:SYSCALL
execve of re-parented process
auditd:SYSCALL
socket: Suspicious creation of AF_UNIX sockets outside expected daemons
auditd:SYSCALL
execve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shells
auditd:SYSCALL
systemctl enable/start: Creation/enablement of custom .service units in /etc/systemd/system
auditd:SYSCALL
execve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd)
auditd:SYSCALL
Execution of network stress tools or anomalies in socket/syscall behavior
auditd:SYSCALL
execve: Commands altering firewall or enabling listeners (iptables, nft, ufw, firewall-cmd, systemctl start *ssh*/*telnet*, ip route add, tcpdump, tshark)
auditd:SYSCALL
execve, unlink
auditd:SYSCALL
execve or socket/connect system calls for processes using RSA handshake
auditd:SYSCALL
execve: parent process is usb/hid device handler, child process bash/python invoked
auditd:SYSCALL
execve: Execution of suspicious exploit binaries targeting security daemons
azure:vmguest
Unexpected execution of cloud agent processes (e.g., WindowsAzureGuestAgent.exe, ssm-agent) followed by arbitrary script or binary execution
containerd:events
New container with suspicious image name or high resource usage
containerd:Events
unusual process spawned from container image context
containerd:runtime
/var/log/containers/*.log
containers:osquery
bandwidth-intensive command execution from within a container namespace
docker:audit
Process execution events within container namespace context
docker:events
Docker/Kubernetes audit of exec/attach (kubectl exec) or unexpected child processes inside container
ebpf:syscalls
process execution or network connect from just-created container PID namespace
ebpf:syscalls
execve
esxi:cron
process or cron activity
esxi:hostd
process execution across cloud VM
esxi:hostd
execution of esxcli with args matching 'storage', 'filesystem', 'core device list'
esxi:hostd
process
esxi:hostd
host daemon events related to VM operations and configuration queries during reconnaissance
commands containing long non-standard tokens or custom lookup tables
esxi:vmkernel
spawned shell or execution environment activity
esxi:vmkernel
Exec
esxi:vmkernel
VMware kernel events for hardware and system configuration access during environmental validation
esxi:vobd
/var/log/vobd.log
etw:Microsoft-Windows-Kernel-Process
provider: ETW CreateProcess events linking msbuild.exe to suspicious children where standard logs are incomplete
fs:fsusage
Execution of disguised binaries
fs:fsusage
binary execution of security_authtrampoline
iOS:unifiedlog
launchd invocation of binary from non-Apple, non-AppStore, or sideloaded location during boot or shortly after unlock
iOS:unifiedlog
Creation of a new process with elevated UID or sensitive entitlements whose binary path is associated with an app container or whose parent/caller is a low-privileged app/webcontent process
kubernetes:apiserver
kubectl exec or kubelet API calls targeting running pods
kubernetes:apiserver
exec into pod followed by secret retrieval via API
linux:osquery
Execution of binary resolved from $PATH not located in /usr/bin or /bin
linux:osquery
process_events
linux:osquery
execution of known firewall binaries
linux:osquery
execve: command like 'date', 'timedatectl', 'hwclock', 'cat /etc/timezone'
linux:osquery
Process execution with LD_PRELOAD or modified library path
linux:osquery
process listening or connecting on non-standard ports
linux:osquery
Processes linked with libssl or crypto libraries making outbound connections
linux:osquery
process execution events for permission modification utilities with command-line analysis
linux:osquery
Anomalous parent PID change
linux:osquery
child process invoking dynamic linker post-ptrace
linux:osquery
socat, ssh, or nc processes opening unexpected ports
linux:osquery
processes modifying environment variables related to history logging
linux:syslog
KERN messages about eBPF program load/verify or LSM denials related to bpf.
linux:syslog
Unauthorized sudo or shell access, especially leading to file changes in /var/www or /srv/http
linux:syslog
systemd-udevd spawning user-defined action from RUN+=
linux:Sysmon
EventCode=1
linux:Sysmon
process creation events linked to container namespaces executing host-level binaries
exec: Execution of defaults, plutil, or common editors (vim/nano) targeting plist files
macos:unifiedlog
process:exec
macos:unifiedlog
Execution of osascript, bash, or Terminal initiated from Mail.app or Safari
macos:unifiedlog
process activity stream
macos:unifiedlog
Post-login execution of unrecognized child process from launchd or loginwindow
macos:unifiedlog
process command line contains base64, -enc, openssl enc -base64
macos:unifiedlog
Execution of process launched via loginwindow session restore
macos:unifiedlog
process: exec + filewrite: ~/.ssh/authorized_keys
macos:unifiedlog
Execution of Java apps or other processes with hidden window attributes
macos:unifiedlog
Process Execution
macos:unifiedlog
process: code or jetbrains-gateway launching with --tunnel or --remote
macos:unifiedlog
log stream --predicate 'processImagePath CONTAINS "curl" OR "osascript"'
macos:unifiedlog
Process using AES/RC4 routines unexpectedly
macos:unifiedlog
process exec events of systemsetup, date, ioreg with command_line parameters indicating time discovery
macos:unifiedlog
execution of osascript, curl, or unexpected automation
macos:unifiedlog
exec /usr/bin/pwpolicy
macos:unifiedlog
Exec of tcpdump, rvictl, custom tools linked to libpcap.A.dylib; sysextd/systemextensionsctl events for NetworkExtension content filters.
macos:unifiedlog
com.apple.firmwareupdater activity or update-firmware binary invoked
macos:unifiedlog
exec or spawn of 'system_profiler', 'ioreg', 'kextstat', 'sysctl', or calls to sysctl API
macos:unifiedlog
process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary
macos:unifiedlog
process:launch
macos:unifiedlog
Execution of scp, rsync, curl with remote destination
macos:unifiedlog
logMessage contains pbpaste or osascript
macos:unifiedlog
process launch of diskutil or system_profiler with SPStorageDataType
macos:unifiedlog
Mail.app executing with parameters updating rules state
macos:unifiedlog
process_name IN ("VBoxManage", "prlctl") AND command CONTAINS ("list", "show")
macos:unifiedlog
exec srm|exec openssl|exec gpg
macos:unifiedlog
Execution of process with DYLD_INSERT_LIBRARIES set
macos:unifiedlog
process and signing chain events
macos:unifiedlog
launchservices events for misleading extensions
macos:unifiedlog
launchd services binding to non-standard ports
macos:unifiedlog
Execution of binaries with unsigned or anomalously signed certificates
macos:unifiedlog
Execution of Terminal, osascript, or other interpreters originating from Mail or Preview
macos:unifiedlog
process events
macos:unifiedlog
Execution of unexpected terminal or web scripts modifying /Library/WebServer/Documents
macos:unifiedlog
Process start of Java or native DB client tools
macos:unifiedlog
loginwindow or tccd-related entries
macos:unifiedlog
Command line invocation of pip3, brew install, npm install from interactive Terminal
macos:unifiedlog
Execution of ssh or sftp without corresponding login event
macos:unifiedlog
launch of remote desktop app or helper binary
macos:unifiedlog
Unexpected processes making network calls based on DNS-derived ports
macos:unifiedlog
launchctl spawning new processes
macos:unifiedlog
launchctl activity and process creation
macos:unifiedlog
Execution of Python, Swift, or other binaries invoking archiving libraries
macos:unifiedlog
Process invoking SSL routines from Security framework
macos:unifiedlog
Execution of binary listed in newly modified LaunchAgent plist
macos:unifiedlog
Execution of bless or nvram modifying boot parameters
macos:unifiedlog
Unexpected processes registered with launchd
macos:unifiedlog
Process launch
macos:unifiedlog
execution of curl, osascript, or unexpected Office processes
macos:unifiedlog
Trust validation failures or bypass attempts during notarization and code signing checks
macos:unifiedlog
process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder}
macos:unifiedlog
Execution of zip, ditto, hdiutil, or openssl by processes not normally associated with archiving
macos:unifiedlog
process execution events for chmod, chown, chflags with unusual parameters or targets
macos:unifiedlog
execve or dylib load from memory without backing file
macos:unifiedlog
exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers.
macos:unifiedlog
Unusual child process tree indicating attempted recovery after crash
macos:unifiedlog
Execution of processes mimicking Apple Security & Privacy GUIs
macos:unifiedlog
execution of curl, git, or Office processes with network connections
macos:unifiedlog
log stream - process subsystem
macos:unifiedlog
Process execution for VBoxHeadless, prl_vm_app, vmware-vmx
macos:unifiedlog
process logs
macos:unifiedlog
command line or log output shows non-standard encoding routines
macos:unifiedlog
Execution of /usr/sbin/installer spawning child process from within /private/tmp or package contents
macos:unifiedlog
execve: Helper tools invoked through XPC executing unexpected binaries
macos:unifiedlog
execution of modified binary without valid signature
macos:unifiedlog
exec: ParentImage in (Terminal, iTerm2) AND Image in (/bin/zsh,/bin/bash,/usr/bin/python*) AND CommandLine matches '(curl|wget).*(\||\|\s*sh|bash)|base64 -D|python -c'
macos:unifiedlog
process created with repeated ICMP or UDP flood behavior
macos:unifiedlog
process: exec
macos:unifiedlog
Child processes of Safari, Chrome, or Firefox executing scripting interpreters
macos:unifiedlog
Execution of older or non-standard interpreters
macos:unifiedlog
process execution events for chmod, chown, chflags with parameter analysis and target path examination
macos:unifiedlog
process, socket, and DNS logs
macos:unifiedlog
Command line containing `trap` or `echo 'trap` written to login shell files
macos:unifiedlog
log collect --predicate
macos:unifiedlog
launchd or osascript spawns process with delay command
exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers
macos:unifiedlog
Execution of zip, ditto, hdiutil, or openssl by non-terminal parent processes
macos:unifiedlog
Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond
macos:unifiedlog
process execution of ssh with -L/-R forwarding flags
macos:unifiedlog
launchd or cron spawning mining binaries
macos:unifiedlog
Process invoking SecKeyCreateRandomKey or asymmetric crypto APIs
macos:unifiedlog
Script interpreter invoked by nginx/apache worker process
macos:unifiedlog
execution of Office binaries with network activity
macos:unifiedlog
launch of bash/zsh/python/osascript targeting key file locations
macos:unifiedlog
execution of /sbin/emond with child processes launched
macos:unifiedlog
shutdown -h now or reboot
macos:unifiedlog
Execution of Code.app, idea, JetBrainsToolbox, eclipse with install/extension flags
macos:unifiedlog
process execution events for system discovery utilities (system_profiler, sysctl, networksetup, ioreg) with parameter analysis
macos:unifiedlog
execution of curl, rclone, or Office apps invoking network sessions
macos:unifiedlog
exec: Execution of kextstat, kextfind, or ioreg targeting driver information
macos:unifiedlog
Process creation involving binaries interacting with resource fork data
macos:unifiedlog
process event
macos:unifiedlog
security OR injection attempts into 1Password OR LastPass
MobileEDR:telemetry
Application writes audio buffer or recorded audio file into application storage directories
MobileEDR:telemetry
Browser or WebView-hosting application brought to foreground and navigates to external content, followed by abnormal state transition, crash, restart, or process spawn behavior
MobileEDR:telemetry
application installed from adb, sideload, or unknown USB source
MobileEDR:telemetry
Application invokes Runtime.exec, ProcessBuilder, JNI-backed command launcher, or equivalent command-execution bridge immediately before shell or command process creation
MobileEDR:telemetry
Managed app invokes lower-level OS process-launch or command-execution behavior before file or network effects, including interpreter-like execution flow where visible to sensor
MobileEDR:telemetry
application execution triggered with unexpected parent context or via indirect invocation (intent redirection or component hijack)
OpenBSM:AuditTrail
open/openat of /dev/bpf*; ioctl BIOCSETF-like operations.
OpenBSM:AuditTrail
BSM audit events for process execution and system call monitoring during reconnaissance
Process
None
WinEventLog:AppLocker
EventCode=8003, 8004
WinEventLog:Microsoft-Windows-DotNETRuntime
Unexpected AppDomain creation events or anomalous AppDomainManager assembly load behavior