Windows: Named Pipe Creation with \pipe\ and \pipe\srvsvc Pattern (EfsPotato)

Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.

FreeUnreviewedSigmahighv1
title: "Windows: Named Pipe Creation with \\pipe\\ and \\pipe\\srvsvc Pattern (EfsPotato)"
id: 8b8342e1-2aa7-4fb8-8479-37dedc051df1
status: test
description: This rule flags Windows named pipe creation events where the PipeName contains both the general \pipe\ namespace and the more specific \pipe\srvsvc marker, matching a pattern used by the EfsPotato hack tool. Creating or targeting named pipes can support stealthy inter-process communication during exploitation and privilege escalation workflows. The detection relies on telemetry that records named pipe creation, specifically PipeName values from Windows pipe creation events (e.g., Sysmon Event ID 17/18) and applies exclusions for context-share and default \pipe\* entries to reduce noise.
references:
  - https://twitter.com/SBousseaden/status/1429530155291193354?s=20
  - https://github.com/zcgonvh/EfsPotato
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_hktl_efspotato.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-23
modified: 2023-12-21
tags:
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1055
logsource:
  product: windows
  category: pipe_created
  definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
  selection:
    PipeName|contains:
      - \pipe\
      - \pipe\srvsvc
  filter_optional_ctx:
    PipeName|contains: \CtxShare
  filter_optional_default:
    PipeName|startswith: \pipe\
  condition: selection and not 1 of filter_optional_*
falsepositives:
  - \pipe\LOCAL\Monitorian
level: high
license: DRL-1.1
related:
  - id: 637f689e-b4a5-4a86-be0e-0100a0a33ba2
    type: derived

What it detects

This rule flags Windows named pipe creation events where the PipeName contains both the general \pipe\ namespace and the more specific \pipe\srvsvc marker, matching a pattern used by the EfsPotato hack tool. Creating or targeting named pipes can support stealthy inter-process communication during exploitation and privilege escalation workflows. The detection relies on telemetry that records named pipe creation, specifically PipeName values from Windows pipe creation events (e.g., Sysmon Event ID 17/18) and applies exclusions for context-share and default \pipe\* entries to reduce noise.

Known false positives

  • \pipe\LOCAL\Monitorian

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.