Detection of Potentially Unwanted Application Named Pipe Usage
This detection analytic identifies the creation or interaction with named pipes associated with potentially unwanted applications (PUAs) or administrative utilities that attackers leverage for lateral movement, command-and-control, or process injection.
This detection focuses on the abuse of Windows named pipes for inter-process communication by potentially unwanted applications (PUAs) or administrative tools, such as PsExec. Attackers frequently leverage named pipes to facilitate lateral movement, hide command-and-control traffic, or perform process injection. By monitoring Sysmon Event IDs 17 (Pipe Created) and 18 (Pipe Connected), security teams can identify anomalous pipe activity that deviates from standard system or enterprise software baseline behavior. While these pipes are essential for legitimate Windows operations and specific administrative software, their presence in unexpected processes or unusual contexts often indicates malicious activity, including use by ransomware groups and advanced persistent threats (APTs). This analytic is intended to surface these anomalies for further investigation within a security operations platform.
Impact
Successful abuse of named pipes can enable attackers to move laterally across a network, execute remote commands, and deploy ransomware or other malicious payloads. This visibility is critical for defending against threats documented in various security advisories, including those related to BlackByte, Cactus, Medusa, Rhysida, and VanHelsing ransomware, as well as activity associated with Sandworm and Volt Typhoon.
Recommendation
- Enable Sysmon logging with Event IDs 17 and 18 on all critical endpoints.
- Deploy the provided detection logic to identify processes accessing named pipes listed in the
pua_named_pipeslookup table. - Tune the detection by adding legitimate organization-specific paths to the exclusion filter to minimize noise from enterprise applications.
- Investigate alerts by pivoting to the process metadata and associated user activity to confirm if the interaction is part of authorized administration or malicious behavior.
Immediate actions
Enable Sysmon Event IDs 17 and 18 logging
Threat Hunt
Search for rare named pipe names in the environment that do not map to known enterprise software.
Data: Sysmon Event ID 17, 18
Detection coverage 1
Detect PUA Named Pipe Creation or Connection
mediumDetects the creation or connection to named pipes associated with potentially unwanted applications (PUAs) using Sysmon Event IDs 17 and 18.
Detection queries are available on the platform. Get full rules →