Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution

Alerts when tttracer.exe is the parent process of a spawned process on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Ensar Şamil, @sblmsrsn, @oscd_initiative (SigmaHQ), DRL 1.1
Published
2020-10-06
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation where the parent executable name ends with '\tttracer.exe', indicating use of the Time Travel Debugging utility. Adversaries may leverage this utility to execute additional malicious processes and perform credential and process dumping actions (for example, targeting lsass.exe). The detection relies on Windows process creation telemetry, specifically the parent image path recorded for child processes.

Related detections9 linkedT1003.001 — drag to rearrange
Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Malicious Credential Dumping via Mimikatz Sekurlsa Command
Malicious Mimikatz Sekurlsa Logonpasswords Credential Dump
Malicious LSASS Credential Dump via ProcDump (via process_creation)
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Malicious LSASS Memory Dump via comsvcs.dll by Salt Typhoon
Malicious LSASS Dump via Process Access (via process_access)
Malicious LSASS Credential Dump with LSASSY - Process (via process_creation)
Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Pivot detection · T1003.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.