Windows: Detect RemCom Named Pipe Creation via \RemCom
Alerts on creation of named pipes with names containing "\RemCom" on Windows.
FreeUnreviewedSigmamediumv1
windows-detect-remcom-named-pipe-creation-via-remcom-d36f87ea
title: "Windows: Detect RemCom Named Pipe Creation via \\RemCom"
id: 8b63d6aa-4cd8-400a-9be9-6b0c2ccfb2d0
related:
- id: 9e77ed63-2ecf-4c7b-b09d-640834882028
type: obsolete
- id: d36f87ea-c403-44d2-aa79-1a0ac7c24456
type: derived
status: test
description: This rule flags Windows named pipe creation where the pipe name contains "\RemCom". RemCom is commonly used for remote command execution-style activity, so default pipe naming can indicate an attacker-controlled communication channel. Telemetry relies on Windows named pipe creation events, such as Sysmon Event ID 17/18, capturing the created PipeName.
references:
- https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
- https://github.com/kavika13/RemCom
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_pua_remcom_default_pipe.yml
author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-08-07
modified: 2023-11-30
tags:
- attack.lateral-movement
- attack.t1021.002
- attack.execution
- attack.t1569.002
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName|contains: \RemCom
condition: selection
falsepositives:
- Legitimate Administrator activity
level: medium
license: DRL-1.1
What it detects
This rule flags Windows named pipe creation where the pipe name contains "\RemCom". RemCom is commonly used for remote command execution-style activity, so default pipe naming can indicate an attacker-controlled communication channel. Telemetry relies on Windows named pipe creation events, such as Sysmon Event ID 17/18, capturing the created PipeName.
Known false positives
- Legitimate Administrator activity
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.