Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
- Product
- windows
- Category
- pipe_created
- Author
- Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
- Published
- 2021-10-08
- Updated
- 2026-07-31
ATT&CK techniques
CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags creation of a named pipe connection targeting the AD FS Windows Internal Database (WID) query pipe (\MICROSOFT##WID\tsql\query). Such access can be used to retrieve AD FS configuration data and related sensitive information that may support token-signing or authentication workflows. It relies on Windows telemetry from named pipe creation events and examines the creating process image to reduce matches from expected service binaries.
Reporting behind it
- github.comhttps://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/ADFSDBNamedPipeConnection.yaml
- o365blog.comhttps://o365blog.com/post/adfs/
- github.comhttps://github.com/Azure/SimuLand
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_adfs_namedpipe_connection_uncommon_tool.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
id: 1bc49183-d440-4539-9fc5-68f28a922d76
status: test
description: This rule flags creation of a named pipe connection targeting the AD FS Windows Internal Database (WID) query pipe (\MICROSOFT##WID\tsql\query). Such access can be used to retrieve AD FS configuration data and related sensitive information that may support token-signing or authentication workflows. It relies on Windows telemetry from named pipe creation events and examines the creating process image to reduce matches from expected service binaries.
references:
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/ADFSDBNamedPipeConnection.yaml
- https://o365blog.com/post/adfs/
- https://github.com/Azure/SimuLand
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_adfs_namedpipe_connection_uncommon_tool.yml
author: Roberto Rodriguez @Cyb3rWard0g, Huntrule Team
date: 2021-10-08
modified: 2023-11-30
tags:
- attack.collection
- attack.t1005
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName: \MICROSOFT##WID\tsql\query
filter_main_generic:
Image|endswith:
- :\Windows\System32\mmc.exe
- :\Windows\system32\svchost.exe
- :\Windows\System32\wsmprovhost.exe
- :\Windows\SysWOW64\mmc.exe
- :\Windows\SysWOW64\wsmprovhost.exe
- :\Windows\WID\Binn\sqlwriter.exe
- \AzureADConnect.exe
- \Microsoft.Identity.Health.Adfs.PshSurrogate.exe
- \Microsoft.IdentityServer.ServiceHost.exe
- \Microsoft.Tri.Sensor.exe
- \sqlservr.exe
- \tssdis.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
type: derived