definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
Image|contains:
'\Microsoft SQL Server\' Image|endswith:
'\Tools\Binn\SQLPS.exe' filter_optional_azure_connected_machine_agent: Image|startswith:
'C:\Program Files\AzureConnectedMachineAgent\GCArcService' Image|endswith:
'\GC\gc_worker.exe' filter_optional_citrix: Image|startswith:
'C:\Program Files\Citrix\' filter_optional_exchange: Image|startswith:
'C:\Program Files\Microsoft\Exchange Server\' filter_main_null: Image:
'None' condition:selection and not 1 of filter_main_* and not 1 of filter_optional_* Falsepositives:
-Programs using PowerShell directly without invocation of a dedicated interpreter. Level:medium