Windows Named Pipe Creation: Detect default DiagTrackEoP POC pipe name
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
FreeUnreviewedSigmacriticalv1
windows-named-pipe-creation-detect-default-diagtrackeop-poc-pipe-name-1f7025a6
title: "Windows Named Pipe Creation: Detect default DiagTrackEoP POC pipe name"
id: 31ce5f94-b345-4601-a989-cbc54c95c23d
status: test
description: This rule alerts on creation of a named pipe whose PipeName contains the specific string used by the DiagTrackEoP proof-of-concept. Attackers can rely on a predictable named pipe to coordinate abuse of the referenced privilege escalation technique. Telemetry required includes Windows named pipe creation events with the PipeName field, typically via Sysmon named pipe event logging.
references:
- https://github.com/Wh04m1001/DiagTrackEoP/blob/3a2fc99c9700623eb7dc7d4b5f314fd9ce5ef51f/main.cpp#L22
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_hktl_diagtrack_eop.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-03
modified: 2023-08-07
tags:
- attack.privilege-escalation
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName|contains: thisispipe
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 1f7025a6-e747-4130-aac4-961eb47015f1
type: derived
What it detects
This rule alerts on creation of a named pipe whose PipeName contains the specific string used by the DiagTrackEoP proof-of-concept. Attackers can rely on a predictable named pipe to coordinate abuse of the referenced privilege escalation technique. Telemetry required includes Windows named pipe creation events with the PipeName field, typically via Sysmon named pipe event logging.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.