Suspicious EastWind Named Pipe Creation

PremiumReviewedSigma · Medium · v1
Product
windows
Category
pipe_created
Author
HuntRule
Published
2026-06-25
Updated
2026-08-28

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation of a named pipe whose name starts with the Y prefix used by EastWind implants for inter-process communication and local tasking. Named pipes with this structure support covert component coordination, so their appearance on endpoints should be correlated with the DRM staging activity.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.