Anomalous Process Lineage - Pair Probability (Path-Keyed) - Threat Hunting

Ranks parent/child process pairs by lift, meaning how much less often the two co-occur than their individual frequencies would predict, so that no single high-volume parent can dominate the results. Sorting on P(child|parent) alone does not work for this pair. In most environments a handful of interpreters and service hosts account for a large share of all process starts, and every rare child of those parents scores lower than any other pairing, burying the classic Office-spawns-a-shell cases. The reciprocal of lift reads directly as "this pairing is N times rarer than chance." The parent is keyed on normalized directory plus image name rather than name alone, so the many distinct binaries called updater.exe or setup.exe remain separate and any hit is immediately attributable to a specific file. Parent paths are normalized before counting (user profiles, version and GUID directories, temp scratch folders) because unnormalized paths split every per-user and per-version copy into its own identity and manufacture false rarity. Universal children (conhost.exe, werfault.exe, wermgr.exe) are excluded. They appear beneath nearly every parent, so their very large baselines float any parent that rarely spawns them to the top on arithmetic alone, with no signal behind it. TUNING Thresholds are n_b (parent baseline), n_a (child baseline) and n_ab (pair rarity). The probability metrics are derived from these and need no separate cutoff. Set the parent floor well below what you would use for a name-keyed hunt, because keying on path fragments each parent's baseline across its install locations, and a floor tuned for pooled names will silently drop tools that deploy a copy of themselves into every directory they serve. Calibrate by checking the distribution of distinct paths per image name in your own data before setting it. BLIND SPOT A masqueraded or newly planted binary has no path baseline of its own, so its parent count is tiny and the floor removes it. Pooling by image

Cortex XDR