{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/behavior-monitoring/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zoom"],"_cs_severities":["medium"],"_cs_tags":["anomaly","endpoint-security","behavior-monitoring"],"_cs_type":"advisory","_cs_vendors":["Zoom Video Communications"],"content_html":"\u003cp\u003eThis detection focuses on identifying the first-time execution of child processes spawned by legitimate Zoom client binaries (zoom.exe or zoom.us). Communication software is a frequent target for attackers looking to leverage legitimate application trust to execute secondary payloads, conduct reconnaissance, or facilitate data exfiltration. By establishing a behavioral baseline of known child processes for Zoom on a per-host basis, security teams can alert on deviations that may indicate malicious activity. Monitoring this parent-child process relationship is critical, as Zoom should rarely spawn system-level binaries, shells, or unusual utilities during normal operation. This analytic helps defenders identify potentially compromised endpoints where the Zoom client has been subverted to perform unauthorized actions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vector can lead to unauthorized code execution with the permissions of the Zoom process, potentially resulting in full endpoint compromise, lateral movement, or data exfiltration. Because this detection identifies anomalous activity, it serves as an early indicator of potential intrusion rather than confirmation of breach, requiring timely investigation to distinguish between benign software updates/plugins and malicious activity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to your SIEM environment to monitor for unknown Zoom child processes. Ensure that Endpoint Detection and Response (EDR) telemetry is correctly mapped to the process_creation log source and that command-line logging is enabled to facilitate the inspection of arguments passed to child processes. Given the experimental nature of this detection, it is recommended to tune the alerts by reviewing initial baselines for common legitimate child processes and suppressing them accordingly. Use the identified suspicious process parent-child relationships to initiate threat hunting activities focused on verifying the legitimacy of the spawned process and its associated command-line arguments.\u003c/p\u003e\n","date_modified":"2026-10-05T12:12:07Z","date_published":"2026-10-05T12:12:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-zoom-child-process/","summary":"Detection of previously unseen child processes spawned by Zoom clients may indicate exploitation of the application for code execution or unauthorized system access.","title":"Monitoring Anomalous Child Processes Spawned by Zoom","url":"https://feed.craftedsignal.io/briefs/2026-10-zoom-child-process/"}],"language":"en","title":"CraftedSignal Threat Feed - Behavior-Monitoring","version":"https://jsonfeed.org/version/1.1"}