Detection of Malicious Windows Named Pipe Usage
This analytic identifies the use of suspicious named pipes on Windows systems, a technique commonly leveraged by malware and post-exploitation frameworks for inter-process communication.
Security teams must monitor for the creation or connection to known suspicious named pipes to detect malicious inter-process communication (IPC). Attackers frequently use named pipes as a stealthy mechanism for data exfiltration, command-and-control (C2) communication, lateral movement, and privilege escalation. This technique is a hallmark of sophisticated post-exploitation toolkits such as Cobalt Strike, Brute Ratel, and various ransomware variants including LockBit and BlackByte.
By leveraging Sysmon EventIDs 17 (Pipe Created) and 18 (Pipe Connected), defenders can gain visibility into how processes interact at the kernel level. This activity is often indicative of process injection or C2 beaconing. The detection of these indicators allows responders to identify potential compromises early in the kill chain, specifically during the execution or persistence phases, before further damage or exfiltration occurs.
Impact
Successful abuse of named pipes facilitates the execution of malicious payloads, persistence mechanisms, and lateral movement within an enterprise environment. Observed threats using these techniques include ransomware operations, infostealers, and remote access trojans (RATs). If left undetected, these IPC channels allow attackers to maintain covert control over compromised hosts, potentially leading to mass data encryption, widespread system compromise, and significant operational disruption.
Recommendation
Deploy the provided Sigma detection rule to monitor for unauthorized named pipe creation or connection events. Ensure Sysmon version 6.0.4 or higher is deployed across all Windows endpoints with logging enabled for EventIDs 17 and 18. Integrate this detection into a SIEM-based workflow to prioritize alerts involving high-risk processes that are not included in the established allowlist.
- Enable Sysmon EventID 17 and 18 telemetry.
- Deploy the provided Sigma rule to detect suspicious pipe activity.
- Configure automated drilldown searches for alerted endpoints to analyze process lineage.
Immediate actions
Deploy Sigma detection for EventID 17 and 18
Threat Hunt
Identify all non-signed binaries creating named pipes
Data: Sysmon EventID 17
Detection coverage 1
Detect Suspicious Windows Named Pipe Creation or Connection
highDetects creation or connection to known suspicious named pipes associated with post-exploitation tools, using Sysmon EventIDs 17 and 18.
Detection queries are available on the platform. Get full rules →