Windows: Named Pipe Creation with \pipe\ and \pipe\srvsvc Pattern (EfsPotato)
Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.
FreeUnreviewedSigmahighv1
windows-named-pipe-creation-with-pipe-and-pipe-srvsvc-pattern-efspotato-637f689e
title: "Windows: Named Pipe Creation with \\pipe\\ and \\pipe\\srvsvc Pattern (EfsPotato)"
id: 8b8342e1-2aa7-4fb8-8479-37dedc051df1
status: test
description: This rule flags Windows named pipe creation events where the PipeName contains both the general \pipe\ namespace and the more specific \pipe\srvsvc marker, matching a pattern used by the EfsPotato hack tool. Creating or targeting named pipes can support stealthy inter-process communication during exploitation and privilege escalation workflows. The detection relies on telemetry that records named pipe creation, specifically PipeName values from Windows pipe creation events (e.g., Sysmon Event ID 17/18) and applies exclusions for context-share and default \pipe\* entries to reduce noise.
references:
- https://twitter.com/SBousseaden/status/1429530155291193354?s=20
- https://github.com/zcgonvh/EfsPotato
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_hktl_efspotato.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-23
modified: 2023-12-21
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1055
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName|contains:
- \pipe\
- \pipe\srvsvc
filter_optional_ctx:
PipeName|contains: \CtxShare
filter_optional_default:
PipeName|startswith: \pipe\
condition: selection and not 1 of filter_optional_*
falsepositives:
- \pipe\LOCAL\Monitorian
level: high
license: DRL-1.1
related:
- id: 637f689e-b4a5-4a86-be0e-0100a0a33ba2
type: derived
What it detects
This rule flags Windows named pipe creation events where the PipeName contains both the general \pipe\ namespace and the more specific \pipe\srvsvc marker, matching a pattern used by the EfsPotato hack tool. Creating or targeting named pipes can support stealthy inter-process communication during exploitation and privilege escalation workflows. The detection relies on telemetry that records named pipe creation, specifically PipeName values from Windows pipe creation events (e.g., Sysmon Event ID 17/18) and applies exclusions for context-share and default \pipe\* entries to reduce noise.
Known false positives
- \pipe\LOCAL\Monitorian
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.