1200KM / simulation
T1559 Inter-Process Communication — Attack Simulation
Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize execution. IPC is also commonly used to avoid situations such as deadlocks, which occurs when processes are stuck in a cyclic waiting pattern. Adversaries may abuse IPC to execute arbitrary code or commands. IPC mechanisms may differ depending on OS,…
Technique description
Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize execution. IPC is also commonly used to avoid situations such as deadlocks, which occurs when processes are stuck in a cyclic waiting pattern. Adversaries may abuse IPC to execute arbitrary code or commands. IPC mechanisms may differ depending on OS,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Create Named Pipe
Procedure 17521690-2183-460f-a182-5dfd6f9f0a7f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Cobalt Strike post-exploitation pipe (4.2 and later)
Procedure 7a48f482-246f-4aeb-9837-21c271ebf244; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Named Pipe Integrity Reduction for Turla's RPC backdoor
Procedure 7a8f8ae9-6b1d-4f7b-88e7-9ea01234eee5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Cobalt Strike Lateral Movement (psexec_psh) pipe
Procedure 830c8b6c-7a70-4f40-b975-8bbe74558acd; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Cobalt Strike post-exploitation pipe (before 4.2)
Procedure 8dbfc15c-527b-4ab0-a272-019f469d367f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Cobalt Strike Artifact Kit pipe
Procedure bd13b9fc-b758-496a-b81a-397462f82c72; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Cobalt Strike SSH (postex_ssh) pipe
Procedure d1f72fa0-5bc2-4b4b-bd1e-43b6e8cfb2e6; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.