Windows: Detect RemCom Named Pipe Creation via \RemCom

Alerts on creation of named pipes with names containing "\RemCom" on Windows.

FreeUnreviewedSigmamediumv1
title: "Windows: Detect RemCom Named Pipe Creation via \\RemCom"
id: 8b63d6aa-4cd8-400a-9be9-6b0c2ccfb2d0
related:
  - id: 9e77ed63-2ecf-4c7b-b09d-640834882028
    type: obsolete
  - id: d36f87ea-c403-44d2-aa79-1a0ac7c24456
    type: derived
status: test
description: This rule flags Windows named pipe creation where the pipe name contains "\RemCom". RemCom is commonly used for remote command execution-style activity, so default pipe naming can indicate an attacker-controlled communication channel. Telemetry relies on Windows named pipe creation events, such as Sysmon Event ID 17/18, capturing the created PipeName.
references:
  - https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
  - https://github.com/kavika13/RemCom
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_pua_remcom_default_pipe.yml
author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-08-07
modified: 2023-11-30
tags:
  - attack.lateral-movement
  - attack.t1021.002
  - attack.execution
  - attack.t1569.002
logsource:
  product: windows
  category: pipe_created
  definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
  selection:
    PipeName|contains: \RemCom
  condition: selection
falsepositives:
  - Legitimate Administrator activity
level: medium
license: DRL-1.1

What it detects

This rule flags Windows named pipe creation where the pipe name contains "\RemCom". RemCom is commonly used for remote command execution-style activity, so default pipe naming can indicate an attacker-controlled communication channel. Telemetry relies on Windows named pipe creation events, such as Sysmon Event ID 17/18, capturing the created PipeName.

Known false positives

  • Legitimate Administrator activity

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.