Suspicious named pipes

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query looks for Named Pipe events that either contain one of the known IOCs or make use of patterns that can be linked to CobaltStrike usage.

Attribute Value
Type Analytic Rule
Solution FalconFriday
ID ddf7c669-db26-4215-acaf-11e2953a04e6
Severity Medium
Status Available
Kind Scheduled
Tactics Execution, DefenseEvasion
Techniques T1559, T1055
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceEvents ActionType == "NamedPipeEvent" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to FalconFriday