Windows Named Pipe Created: \REDSUN (RedSun)

Flags creation of the named pipe \REDSUN on Windows, consistent with RedSun-style IPC used during exploitation.

FreeUnreviewedSigmacriticalv1
title: "Windows Named Pipe Created: \\REDSUN (RedSun)"
id: 4ebb5799-89e5-4873-a897-617c8ac06a20
status: experimental
description: This rule detects creation of a Windows named pipe with the hardcoded name \REDSUN. Attack tooling may use a specific pipe name to synchronize components and establish inter-process communication, including for privilege escalation workflows. Telemetry relies on pipe creation events that include the created pipe name.
references:
  - https://github.com/Nightmare-Eclipse/RedSun/blob/7456cc8cf066f5e5fc6cdf7d3272a466ebd6b2f6/RedSun.cpp#L591
  - https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2026/Exploits/RedSun/pipe_created_win_exploit_redsun_named_pipe.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost, Huntrule Team
date: 2026-04-17
tags:
  - attack.privilege-escalation
  - attack.stealth
  - attack.defense-impairment
  - attack.t1055
  - attack.t1685
  - detection.emerging-threats
logsource:
  category: pipe_created
  product: windows
detection:
  selection:
    PipeName: \REDSUN
  condition: selection
falsepositives:
  - Unlikely
level: critical
regression_tests_path: regression_data/rules-emerging-threats/2026/Exploits/RedSun/pipe_created_win_exploit_redsun_named_pipe/info.yml
license: DRL-1.1
related:
  - id: 9b4e7c2a-3f6d-4a8b-b5e9-1c7d3f2e6a4b
    type: derived

What it detects

This rule detects creation of a Windows named pipe with the hardcoded name \REDSUN. Attack tooling may use a specific pipe name to synchronize components and establish inter-process communication, including for privilege escalation workflows. Telemetry relies on pipe creation events that include the created pipe name.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.