{"id":"fe3ac066-98bb-432a-b1e7-a5229cb39d4a","title":"Malicious Named Pipe Created","description":"Detects the creation of a named pipe seen used by known APTs or malware.","author":"Florian Roth (Nextron Systems), blueteam0ps, elhoim","status":"test","level":"critical","date":"2017-11-06","modified":"2023-08-07","tags":["attack.privilege-escalation","attack.stealth","attack.t1055"],"technique_ids":["T1055"],"logsource":{"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"},"falsepositives":["Unknown"],"references":["https://securelist.com/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/71275/","https://securelist.com/faq-the-projectsauron-apt/75533/","https://web.archive.org/web/20180725233601/https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf","https://www.us-cert.gov/ncas/alerts/TA17-117A","https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html","https://thedfirreport.com/2020/06/21/snatch-ransomware/","https://github.com/RiccardoAncarani/LiquidSnake","https://www.accenture.com/us-en/blogs/cyber-defense/turla-belugasturgeon-compromises-government-entity","https://us-cert.cisa.gov/ncas/analysis-reports/ar19-304a","https://download.bitdefender.com/resources/files/News/CaseStudies/study/115/Bitdefender-Whitepaper-PAC-A4-en-EN1.pdf","https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/","https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/"],"source_path":"rules/windows/pipe_created/pipe_created_susp_malicious_namedpipes.yml","source_sha256":"4a6259c8110092fe4e9b8beaa6491829637b689eb84fad9384035c9841d9b0e6","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/pipe_created/pipe_created_susp_malicious_namedpipes.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Malicious Named Pipe Created\nid: fe3ac066-98bb-432a-b1e7-a5229cb39d4a\nstatus: test\ndescription: Detects the creation of a named pipe seen used by known APTs or malware.\nreferences:\n    - https://securelist.com/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/71275/\n    - https://securelist.com/faq-the-projectsauron-apt/75533/\n    - https://web.archive.org/web/20180725233601/https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-annex-b-final.pdf\n    - https://www.us-cert.gov/ncas/alerts/TA17-117A\n    - https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html\n    - https://thedfirreport.com/2020/06/21/snatch-ransomware/\n    - https://github.com/RiccardoAncarani/LiquidSnake\n    - https://www.accenture.com/us-en/blogs/cyber-defense/turla-belugasturgeon-compromises-government-entity\n    - https://us-cert.cisa.gov/ncas/analysis-reports/ar19-304a\n    - https://download.bitdefender.com/resources/files/News/CaseStudies/study/115/Bitdefender-Whitepaper-PAC-A4-en-EN1.pdf\n    - https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/\n    - https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/\nauthor: Florian Roth (Nextron Systems), blueteam0ps, elhoim\ndate: 2017-11-06\nmodified: 2023-08-07\ntags:\n    - attack.privilege-escalation\n    - attack.stealth\n    - attack.t1055\nlogsource:\n    product: windows\n    category: pipe_created\n    definition: 'Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575'\ndetection:\n    selection:\n        PipeName:\n            - '\\46a676ab7f179e511e30dd2dc41bd388'  # Project Sauron\n            - '\\583da945-62af-10e8-4902-a8f205c72b2e'  # SolarWinds SUNBURST malware\n            - '\\6e7645c4-32c5-4fe3-aabf-e94c2f4370e7'  # LiquidSnake\n            - '\\9f81f59bc58452127884ce513865ed20'  # Project Sauron\n            - '\\adschemerpc'  # Turla HyperStack\n            - '\\ahexec'  # Sofacy group malware\n            - '\\AnonymousPipe'  # Hidden Cobra Hoplight\n            - '\\bc31a7'  # Pacifier\n            - '\\bc367'  # Pacifier\n            - '\\bizkaz'  # Snatch Ransomware\n            - '\\csexecsvc' # CSEXEC default\n            - '\\dce_3d' # Qbot\n            - '\\e710f28d59aa529d6792ca6ff0ca1b34'  # Project Sauron\n            - '\\gruntsvc' # Covenant default\n            - '\\isapi_dg'  # Uroburos Malware\n            - '\\isapi_dg2'  # Uroburos Malware\n            - '\\isapi_http'  # Uroburos Malware\n            - '\\jaccdpqnvbrrxlaf' # PoshC2 default\n            - '\\lsassw'  # Wild Neutron APT malware\n            - '\\NamePipe_MoreWindows'  # Cloud Hopper - RedLeaves\n            - '\\pcheap_reuse'  # Pipe used by Equation Group malware\n            - '\\Posh*' # PoshC2 default\n            - '\\rpchlp_3'  # Project Sauron\n            - '\\sdlrpc'  # Cobra Trojan\n            - '\\svcctl' # Crackmapexec smbexec default\n            - '\\testPipe'  # Emissary Panda Hyperbro\n            - '\\winsession'  # Wild Neutron APT malware\n            # - '\\status_*' # CS default  https://github.com/SigmaHQ/sigma/issues/253\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1055","id":"T1055","name":"Process Injection","page":"techniques/enterprise/T1055/"}],"data_path":"data/detection-rules/fe3ac066-98bb-432a-b1e7-a5229cb39d4a.json","kind":"sigma"}
