Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-09-01
Updated
2026-09-01

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects uses the Tchopper tool by remotely creating multiple services via named pipes.

Related detections6 linkedT1569 — drag to rearrange
Obfuscated Massive Service Failures - Tchopper (via system)
Malicious Massive Remote Service Creation via Named Pipes - TChopper, CME (via security)
KrbRelayUp Service Installation - Native (via system)
Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Windows PsExec Execution Triggered by psexec.exe Process Creation
Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
Pivot detection · T1569 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.