Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize execution. IPC is also commonly used to avoid situations such as deadlocks, which occurs when processes are stuck in a cyclic waiting pattern.
Adversaries may abuse IPC to execute arbitrary code or commands. IPC mechanisms may differ depending on OS, but typically exists in a form accessible through programming languages/libraries or native interfaces such as Windows Dynamic Data Exchange or Component Object Model. Linux environments support several different IPC mechanisms, two of which being sockets and pipes. Higher level execution mediums, such as those of Command and Scripting Interpreters, may also leverage underlying IPC mechanisms. Adversaries may also use Remote Services such as Distributed Component Object Model to facilitate remote IPC execution.
Rules on DetectionCode tagged with T1559 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| CMSTP Execution Process Access | high | windows / process_access | T1559.001 |
| DNS Query Request By Regsvr32.EXE | medium | windows / dns_query | T1559.001 |
| Enable Microsoft Dynamic Data Exchange | medium | windows / registry_set | T1559.002 |
| Network Connection Initiated By Regsvr32.EXE | medium | windows / network_connection | T1559.001 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Process Writing DynamicWrapperX | Hunting | NULL | Sysmon EventID 11 | T1559.001 |
| Windows Anonymous Pipe Activity | Hunting | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1559 |
| Windows PUA Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1559 |
| Windows RMM Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1559 |
| Windows Suspicious C2 Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1559 |
| Windows Suspicious Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1559 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareCyclops Blink | Cyclops Blink has the ability to create a pipe to enable inter-process communication. |
| MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| MalwareHyperStack | HyperStack can connect to the IPC$ share on remote machines. |
| MalwareLunarWeb | LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe. |
| MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory. |
| MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| MalwareOilBooster | OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.