Skip to content
Threat Feed
high advisory

Detection of Malicious Windows Named Pipe Usage

This analytic identifies the use of suspicious named pipes on Windows systems, a technique commonly leveraged by malware and post-exploitation frameworks for inter-process communication.

Security teams must monitor for the creation or connection to known suspicious named pipes to detect malicious inter-process communication (IPC). Attackers frequently use named pipes as a stealthy mechanism for data exfiltration, command-and-control (C2) communication, lateral movement, and privilege escalation. This technique is a hallmark of sophisticated post-exploitation toolkits such as Cobalt Strike, Brute Ratel, and various ransomware variants including LockBit and BlackByte.

By leveraging Sysmon EventIDs 17 (Pipe Created) and 18 (Pipe Connected), defenders can gain visibility into how processes interact at the kernel level. This activity is often indicative of process injection or C2 beaconing. The detection of these indicators allows responders to identify potential compromises early in the kill chain, specifically during the execution or persistence phases, before further damage or exfiltration occurs.

Impact

Successful abuse of named pipes facilitates the execution of malicious payloads, persistence mechanisms, and lateral movement within an enterprise environment. Observed threats using these techniques include ransomware operations, infostealers, and remote access trojans (RATs). If left undetected, these IPC channels allow attackers to maintain covert control over compromised hosts, potentially leading to mass data encryption, widespread system compromise, and significant operational disruption.

Recommendation

Deploy the provided Sigma detection rule to monitor for unauthorized named pipe creation or connection events. Ensure Sysmon version 6.0.4 or higher is deployed across all Windows endpoints with logging enabled for EventIDs 17 and 18. Integrate this detection into a SIEM-based workflow to prioritize alerts involving high-risk processes that are not included in the established allowlist.

  • Enable Sysmon EventID 17 and 18 telemetry.
  • Deploy the provided Sigma rule to detect suspicious pipe activity.
  • Configure automated drilldown searches for alerted endpoints to analyze process lineage.

Immediate actions

Deploy Sigma detection for EventID 17 and 18

Detection Engineering 48h

Threat Hunt

Identify all non-signed binaries creating named pipes

T1055 high high confidence hunt now

Data: Sysmon EventID 17

Detection coverage 1

Detect Suspicious Windows Named Pipe Creation or Connection

high

Detects creation or connection to known suspicious named pipes associated with post-exploitation tools, using Sysmon EventIDs 17 and 18.

sigma tactics: execution techniques: T1055 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →