Windows Named Pipe Created for PowerShell Host (PSHost)

Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.

FreeUnreviewedSigmainformationalv1
title: Windows Named Pipe Created for PowerShell Host (PSHost)
id: d0c8bc83-fee5-48bf-a749-3f0669dfb8e2
related:
  - id: 58cb02d5-78ce-4692-b3e1-dce850aae41a
    type: derived
  - id: ac7102b4-9e1e-4802-9b4f-17c5524c015c
    type: derived
status: test
description: This rule flags Windows named pipe creation events where the pipe name starts with \PSHost, indicating PowerShell host initialization via named pipes. Attackers may use PowerShell execution capabilities to run scripts in a way that triggers these IPC artifacts. The detection relies on telemetry from Windows named pipe creation events (for example, Sysmon pipe-created/pipe-connected events) and matches the pipe name prefix.
references:
  - https://threathunterplaybook.com/hunts/windows/190610-PwshAlternateHosts/notebook.html
  - https://threathunterplaybook.com/hunts/windows/190410-LocalPwshExecution/notebook.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_powershell_execution_pipe.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2019-09-12
modified: 2023-11-30
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: pipe_created
  definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
  selection:
    PipeName|startswith: \PSHost
  condition: selection
falsepositives:
  - Likely
level: informational
license: DRL-1.1

What it detects

This rule flags Windows named pipe creation events where the pipe name starts with \PSHost, indicating PowerShell host initialization via named pipes. Attackers may use PowerShell execution capabilities to run scripts in a way that triggers these IPC artifacts. The detection relies on telemetry from Windows named pipe creation events (for example, Sysmon pipe-created/pipe-connected events) and matches the pipe name prefix.

Known false positives

  • Likely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.