Detection of Malicious Use of RMM Named Pipes
This brief details the detection of unauthorized processes or tools interacting with named pipes associated with Remote Monitoring and Management (RMM) software, a technique used for persistence and command-and-control.
Attackers frequently abuse the Inter-Process Communication (IPC) mechanisms provided by Windows named pipes to facilitate persistence, command-and-control (C2) operations, and inter-process communication. Remote Monitoring and Management (RMM) tools often rely on these pipes for legitimate remote administration. However, threat actors leverage these same, well-known pipe signatures to hide malicious activity, conduct lateral movement, or execute shellcode injections. This detection focuses on identifying unauthorized processes that create or connect to these suspicious named pipes, which are often used by offensive toolsets. Defenders should prioritize visibility into Sysmon EventIDs 17 (Pipe Created) and 18 (Pipe Connected) to differentiate between legitimate RMM usage and adversarial abuse.
Impact
Successful abuse of RMM named pipes can grant attackers unauthorized control over affected endpoints, enable persistent access despite system reboots, and facilitate the deployment of ransomware or modular malware. This technique is commonly associated with several high-profile threat campaigns, including ransomware deployments and sophisticated C2 frameworks.
Recommendation
- Deploy the provided Sigma rule to your SIEM to monitor for unauthorized access to suspicious named pipes.
- Baseline legitimate RMM traffic within your environment to establish a whitelist of authorized processes and their associated named pipes.
- Ensure Sysmon is configured to capture EventIDs 17 and 18 across all Windows endpoints to support this detection.
- Investigate any alerts generated by non-standard processes (e.g., binaries running from user directories or non-system paths) that interact with known RMM-related named pipes.
Immediate actions
Deploy Sysmon 17/18 logging policy to endpoints.
Threat Hunt
Search for unauthorized processes creating pipes not in the whitelist.
Data: Sysmon EventID 17/18
Mitigations
Whitelist known internal RMM agents by path and pipe name.
RMM software abuse
Detection coverage 1
Detect Suspicious RMM Named Pipe Activity
mediumDetects creation or connection to known suspicious named pipes often used by offensive tools or RMM software abuse.
Detection queries are available on the platform. Get full rules →