Privilege Escalation via Named Pipe Impersonation

 Original Source: [Sigma source]
Title: Privilege Escalation via Named Pipe Impersonation
Status: test
Description:Detects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.
References:
  -https://www.elastic.co/guide/en/security/current/privilege-escalation-via-named-pipe-impersonation.html
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-27
modified:2022-12-30
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_name:
    - Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
    - OriginalFileName:
      - 'Cmd.Exe'
      - 'PowerShell.EXE'
  selection_args:
    CommandLine|contains|all:
      -'echo'
      -'>'
      -'\\\\.\\pipe\\'

  condition:all of selection*
Falsepositives:
  -Other programs that cause these patterns (please report)
Level: high