{"id":"T1564.011","name":"Ignore Process Interrupts","url":"https://attack.mitre.org/techniques/T1564/011","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0067","stix_id":"x-mitre-detection-strategy--29d1e77a-a05e-4ead-8272-b254992cd2ba","name":"Detection Strategy for Ignore Process Interrupts","url":"https://attack.mitre.org/detectionstrategies/DET0067","analytics":[{"id":"AN0181","stix_id":"x-mitre-analytic--8d75d4b3-6748-4d1c-936c-129ee56a12a5","name":"Analytic 0181","description":"Execution of processes using nohup or shell redirection to ignore SIGHUP and continue running after session termination. Defender perspective: correlation between commands including nohup, disowned jobs, or `&` suffix with continued process execution after parent terminal exit.","url":"https://attack.mitre.org/detectionstrategies/DET0067#AN0181","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve call including 'nohup' or trailing '&'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"process persists beyond parent shell termination","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"IgnoredSignals","description":"Specific signals to monitor (e.g., SIGHUP, SIGINT) depending on environment baseline."},{"field":"ProcessLifetimeThreshold","description":"Duration a process continues running after session logout, adjustable to reduce noise from benign long-lived jobs."}],"live":true,"detection_strategies":["DET0067"],"techniques":["T1564.011"]},{"id":"AN0182","stix_id":"x-mitre-analytic--80e9341d-7ea4-4684-8f27-54566e996ce6","name":"Analytic 0182","description":"PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as `-ErrorAction SilentlyContinue`. Defender perspective: detecting discrepancies between suppressed error arguments and continued execution behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0067#AN0182","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredCmdlets","description":"List of PowerShell cmdlets where suppressed error handling is suspicious (e.g., Invoke-Expression, Invoke-WebRequest)."},{"field":"ErrorActionThreshold","description":"Frequency of suppressed error actions within time window that should trigger detection."}],"live":true,"detection_strategies":["DET0067"],"techniques":["T1564.011"]},{"id":"AN0183","stix_id":"x-mitre-analytic--c9079261-caa7-4cfe-8be6-1359db599d27","name":"Analytic 0183","description":"Use of nohup, disown, or AppleScript constructs to suppress process interrupts. Defender perspective: commands containing nohup or hidden background tasks (`osascript` with persistent execution) correlated with processes surviving user logouts.","url":"https://attack.mitre.org/detectionstrategies/DET0067#AN0183","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"nohup, disown, or osascript execution patterns","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"background process persists beyond user logout","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedShells","description":"Shells or interpreters where nohup/disown usage is suspicious, configurable to environment."},{"field":"PersistenceCorrelationWindow","description":"Time window to correlate process continuation after logout with suspicious commands."}],"live":true,"detection_strategies":["DET0067"],"techniques":["T1564.011"]}],"live":true,"version":"1.0","techniques":["T1564.011"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}