Skip to content

Process Tree

Definition

A structured representation of running processes showing each process alongside its parent. Malware frequently spawns command shells or other processes from unexpected parents, such as a web server process or a document reader. The tree makes these anomalies visible where a flat list would hide them.

Shows
Parent-child process relationships
Reveals
Anomalous parent processes
Common signal
Office app spawning cmd.exe / powershell.exe
Source
Live capture or memory image

Common questions

Why is a process tree more useful than a flat process list for detecting an intrusion?+

A flat list shows every running process with equal weight, but the tree structure shows which process launched which, so an analyst immediately spots a suspicious lineage, such as a web server or document reader spawning a command shell, a relationship invisible when processes are listed alphabetically or by PID alone.

Can a process tree be trusted if the malware has already terminated its parent process?+

Not fully. Some malware deliberately kills or reparents its launching process to obscure the tree, which is why analysts corroborate the tree with other artefacts such as event logs, prefetch files, or network connection records rather than relying on the tree in isolation.

Related terms

ARP Cache
A table held in memory that maps IP addresses to hardware (MAC) addresses for recently contacted hosts on the local network. ARP...
DNS Resolver Cache
A temporary store of DNS query results held by the operating system. Entries reveal which domain names a host has recently resolved,...
Live Response
The process of collecting evidence and triage data from a running system without first powering it down. Preserves volatile artefacts that would...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
Trusted Response Kit
A portable collection of statically compiled, cryptographically verified forensic tools stored on write-protected media. Used during live response to avoid executing potentially...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.