First Time Seen Remote Named Pipe

 Original Source: [Sigma source]
Title: First Time Seen Remote Named Pipe
Status: test
Description:This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
References:
  -https://twitter.com/menasec1/status/1104489274387451904
Author: Samir Bousseaden
Date: 2019-04-03
modified:2023-03-14
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • service: security
  • definition: The advanced audit policy setting "Object Access > Audit Detailed File Share" must be configured for Success/Failure
Detection:
  selection1:
    EventID: '5145'
    ShareName: '\\\\\*\\IPC$'
  false_positives:
    RelativeTargetName:
      -'atsvc'
      -'samr'
      -'lsarpc'
      -'lsass'
      -'winreg'
      -'netlogon'
      -'srvsvc'
      -'protected_storage'
      -'wkssvc'
      -'browser'
      -'netdfs'
      -'svcctl'
      -'spoolss'
      -'ntsvcs'
      -'LSM_API_service'
      -'HydraLsPipe'
      -'TermSrv_API_service'
      -'MsFteWds'
      -'sql\query'
      -'eventlog'

  condition:selection1 and not false_positives
Falsepositives:
  -Update the excluded named pipe to filter out any newly observed legit named pipe
Level: high