Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
FreeReviewedSigma · Critical · v2
- Product
- windows
- Category
- pipe_created
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-08-03
- Updated
- 2026-07-31
What it detects
This rule alerts on creation of a named pipe whose name contains the specific string fragment 'thisispipe', associated with the DiagTrackEoP proof-of-concept. Attackers may use default named pipes as part of local privilege escalation workflows, so spotting unusual pipe creation can help detect exploitation attempts. The detection relies on Windows telemetry that records named pipe creation events, such as Sysmon Named Pipe events (Event ID 17/18) with pipe name visibility.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-named-pipe-creation-detect-default-diagtrackeop-poc-pipe-name-1f7025a6
title: Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
id: 31ce5f94-b345-4601-a989-cbc54c95c23d
status: test
description: This rule alerts on creation of a named pipe whose name contains the specific string fragment 'thisispipe', associated with the DiagTrackEoP proof-of-concept. Attackers may use default named pipes as part of local privilege escalation workflows, so spotting unusual pipe creation can help detect exploitation attempts. The detection relies on Windows telemetry that records named pipe creation events, such as Sysmon Named Pipe events (Event ID 17/18) with pipe name visibility.
references:
- https://github.com/Wh04m1001/DiagTrackEoP/blob/3a2fc99c9700623eb7dc7d4b5f314fd9ce5ef51f/main.cpp#L22
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_hktl_diagtrack_eop.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-03
modified: 2023-08-07
tags:
- attack.privilege-escalation
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName|contains: thisispipe
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 1f7025a6-e747-4130-aac4-961eb47015f1
type: derived