Skip to content
Threat Feed
medium advisory

Detection of Malicious Use of RMM Named Pipes

This brief details the detection of unauthorized processes or tools interacting with named pipes associated with Remote Monitoring and Management (RMM) software, a technique used for persistence and command-and-control.

Attackers frequently abuse the Inter-Process Communication (IPC) mechanisms provided by Windows named pipes to facilitate persistence, command-and-control (C2) operations, and inter-process communication. Remote Monitoring and Management (RMM) tools often rely on these pipes for legitimate remote administration. However, threat actors leverage these same, well-known pipe signatures to hide malicious activity, conduct lateral movement, or execute shellcode injections. This detection focuses on identifying unauthorized processes that create or connect to these suspicious named pipes, which are often used by offensive toolsets. Defenders should prioritize visibility into Sysmon EventIDs 17 (Pipe Created) and 18 (Pipe Connected) to differentiate between legitimate RMM usage and adversarial abuse.

Impact

Successful abuse of RMM named pipes can grant attackers unauthorized control over affected endpoints, enable persistent access despite system reboots, and facilitate the deployment of ransomware or modular malware. This technique is commonly associated with several high-profile threat campaigns, including ransomware deployments and sophisticated C2 frameworks.

Recommendation

  1. Deploy the provided Sigma rule to your SIEM to monitor for unauthorized access to suspicious named pipes.
  2. Baseline legitimate RMM traffic within your environment to establish a whitelist of authorized processes and their associated named pipes.
  3. Ensure Sysmon is configured to capture EventIDs 17 and 18 across all Windows endpoints to support this detection.
  4. Investigate any alerts generated by non-standard processes (e.g., binaries running from user directories or non-system paths) that interact with known RMM-related named pipes.

Immediate actions

Deploy Sysmon 17/18 logging policy to endpoints.

IT Operations 48h

Threat Hunt

Search for unauthorized processes creating pipes not in the whitelist.

T1559 high medium confidence hunt now

Data: Sysmon EventID 17/18

Mitigations

Whitelist known internal RMM agents by path and pipe name.

short_term Security Operations

RMM software abuse

Detection coverage 1

Detect Suspicious RMM Named Pipe Activity

medium

Detects creation or connection to known suspicious named pipes often used by offensive tools or RMM software abuse.

sigma tactics: command_and_control, persistence techniques: T1021.002, T1055, T1559 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →