Masquerading Cobalt Strike GetSystem Named-Pipe Impersonation Pattern (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-18
Updated
2026-08-28

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the command shell pattern used by Cobalt Strike's getsystem, in which cmd.exe echoes data into a named pipe to trigger SYSTEM token impersonation via a briefly created service. Cobalt Strike is among the most prevalent adversary tools in the Red Canary Threat Detection Report, and this privilege-escalation primitive is a high-fidelity signal of an active beacon. Detecting the echo-to-pipe command surfaces hands-on escalation.

Related detections9 linkedT1134.001 — drag to rearrange
Malicious Potato Family Privilege Escalation Tool Execution (via process_creation)
Malicious Named Pipe kesknq for Token Impersonation (via pipe_created)
SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
SharpImpersonation Tool Execution on Windows
Windows Process Creation: Impersonate.exe HackTool Execution
Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Windows: Detect Named Pipe Creation with Koh Default Names
Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Masquerading Cobalt Strike GetSystem Named-Pipe Impersonation Pattern (via process_creation)
Pivot detection · T1134.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.