Skip to content
Threat Feed
medium advisory

Detection of Potentially Unwanted Application Named Pipe Usage

This detection analytic identifies the creation or interaction with named pipes associated with potentially unwanted applications (PUAs) or administrative utilities that attackers leverage for lateral movement, command-and-control, or process injection.

This detection focuses on the abuse of Windows named pipes for inter-process communication by potentially unwanted applications (PUAs) or administrative tools, such as PsExec. Attackers frequently leverage named pipes to facilitate lateral movement, hide command-and-control traffic, or perform process injection. By monitoring Sysmon Event IDs 17 (Pipe Created) and 18 (Pipe Connected), security teams can identify anomalous pipe activity that deviates from standard system or enterprise software baseline behavior. While these pipes are essential for legitimate Windows operations and specific administrative software, their presence in unexpected processes or unusual contexts often indicates malicious activity, including use by ransomware groups and advanced persistent threats (APTs). This analytic is intended to surface these anomalies for further investigation within a security operations platform.

Impact

Successful abuse of named pipes can enable attackers to move laterally across a network, execute remote commands, and deploy ransomware or other malicious payloads. This visibility is critical for defending against threats documented in various security advisories, including those related to BlackByte, Cactus, Medusa, Rhysida, and VanHelsing ransomware, as well as activity associated with Sandworm and Volt Typhoon.

Recommendation

  • Enable Sysmon logging with Event IDs 17 and 18 on all critical endpoints.
  • Deploy the provided detection logic to identify processes accessing named pipes listed in the pua_named_pipes lookup table.
  • Tune the detection by adding legitimate organization-specific paths to the exclusion filter to minimize noise from enterprise applications.
  • Investigate alerts by pivoting to the process metadata and associated user activity to confirm if the interaction is part of authorized administration or malicious behavior.

Immediate actions

Enable Sysmon Event IDs 17 and 18 logging

IT Operations 48h

Threat Hunt

Search for rare named pipe names in the environment that do not map to known enterprise software.

T1559 medium medium confidence hunt now

Data: Sysmon Event ID 17, 18

Detection coverage 1

Detect PUA Named Pipe Creation or Connection

medium

Detects the creation or connection to named pipes associated with potentially unwanted applications (PUAs) using Sysmon Event IDs 17 and 18.

sigma tactics: command_and_control, persistence techniques: T1559 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →