Windows Named Pipe Creation: CSExec Default \csexecsvc Pipe
Alerts on Windows named pipe creations with pipe names containing \csexecsvc, matching CSExec’s default pipe.
FreeUnreviewedSigmamediumv1
windows-named-pipe-creation-csexec-default-csexecsvc-pipe-f318b911
title: "Windows Named Pipe Creation: CSExec Default \\csexecsvc Pipe"
id: a5ec1f40-9b5a-4768-bd68-978955b4078f
related:
- id: 9e77ed63-2ecf-4c7b-b09d-640834882028
type: obsolete
- id: f318b911-ea88-43f4-9281-0de23ede628e
type: derived
status: test
description: This rule flags Windows named pipe creation events where the pipe name contains "\csexecsvc", which corresponds to the CSExec default pipe naming. Such pipes can be used for lateral movement and execution by exposing an IPC endpoint to other processes. It relies on telemetry from named pipe creation events (e.g., Sysmon Named Pipe events) that include the created PipeName.
references:
- https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view
- https://github.com/malcomvetter/CSExec
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_pua_csexec_default_pipe.yml
author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-08-07
modified: 2023-11-30
tags:
- attack.lateral-movement
- attack.t1021.002
- attack.execution
- attack.t1569.002
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName|contains: \csexecsvc
condition: selection
falsepositives:
- Legitimate Administrator activity
level: medium
license: DRL-1.1
What it detects
This rule flags Windows named pipe creation events where the pipe name contains "\csexecsvc", which corresponds to the CSExec default pipe naming. Such pipes can be used for lateral movement and execution by exposing an IPC endpoint to other processes. It relies on telemetry from named pipe creation events (e.g., Sysmon Named Pipe events) that include the created PipeName.
Known false positives
- Legitimate Administrator activity
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.