Suspicious named pipe created
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detects when a suspicious remote named pipe is observed, which could indicate lateral movement or remote execution attempts by malicious actors.
Strategy
Monitoring of Windows event logs where @evt.id
is 5145
and grouping by @Event.System.Computer
, where A network share object was checked to see whether client can be granted desired access. The value that was observed was unusual, which made it suspicious.
Triage & Response
Verify if the exection of the suspicious pipe on {{@@Event.System.Computer}}
is expected. If the execution was not intended isolate the system.