Windows named pipe creation matching DiagTrackEoP POC pipe name fragment

Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.

FreeReviewedSigma · Critical · v2
Product
windows
Category
pipe_created
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-03
Updated
2026-07-31
title: Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
id: 31ce5f94-b345-4601-a989-cbc54c95c23d
status: test
description: This rule alerts on creation of a named pipe whose name contains the specific string fragment 'thisispipe', associated with the DiagTrackEoP proof-of-concept. Attackers may use default named pipes as part of local privilege escalation workflows, so spotting unusual pipe creation can help detect exploitation attempts. The detection relies on Windows telemetry that records named pipe creation events, such as Sysmon Named Pipe events (Event ID 17/18) with pipe name visibility.
references:
  - https://github.com/Wh04m1001/DiagTrackEoP/blob/3a2fc99c9700623eb7dc7d4b5f314fd9ce5ef51f/main.cpp#L22
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_hktl_diagtrack_eop.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-08-03
modified: 2023-08-07
tags:
  - attack.privilege-escalation
logsource:
  product: windows
  category: pipe_created
  definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
  selection:
    PipeName|contains: thisispipe
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 1f7025a6-e747-4130-aac4-961eb47015f1
    type: derived