Skip to content

Commit 1836897

Browse files
Merge pull request #151 from Neo23x0/patch-8
Important and relevant NamedPipe names
2 parents 80d268d + 83b7a06 commit 1836897

File tree

1 file changed

+17
-5
lines changed

1 file changed

+17
-5
lines changed

sysmonconfig-export.xml

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -849,11 +849,23 @@
849849
<!--ADDITIONAL REFERENCE: [ https://blog.cobaltstrike.com/2015/10/07/named-pipe-pivoting/ ] -->
850850

851851
<!--DATA: UtcTime, ProcessGuid, ProcessId, PipeName, Image-->
852-
<RuleGroup name="" groupRelation="or">
853-
<PipeEvent onmatch="include">
854-
<!--NOTE: Using incide with no rules means nothing in this section will be logged-->
855-
</PipeEvent>
856-
</RuleGroup>
852+
<RuleGroup name="" groupRelation="or">
853+
<PipeEvent onmatch="include">
854+
<!-- Remote Command Execution Tools -->
855+
<PipeName condition="contains any">paexec;remcom;csexec</PipeName>
856+
<!-- Password or Credential Dumpers -->
857+
<PipeName condition="contains any">\lsadump;\cachedump;\wceservicepipe</PipeName>
858+
<!-- Malware -->
859+
<PipeName condition="contains any">\isapi_http;\isapi_dg;\isapi_dg2;\sdlrpc;\ahexec;\winsession;\lsassw;\46a676ab7f179e511e30dd2dc41bd388;\9f81f59bc58452127884ce513865ed20;\e710f28d59aa529d6792ca6ff0ca1b34;\rpchlp_3;\NamePipe_MoreWindows;\pcheap_reuse;\gruntsvc;\583da945-62af-10e8-4902-a8f205c72b2e;\bizkaz;\svcctl;\Posh;\jaccdpqnvbrrxlaf;\csexecsvc</PipeName>
860+
<PipeName condition="contains any">\atctl;\userpipe;\iehelper;\sdlrpc;\comnap</PipeName>
861+
<!-- Cobalt Strike Pipe Names -->
862+
<PipeName condition="contains all">MSSE-;-server</PipeName>
863+
<PipeName condition="begin with">\postex_</PipeName>
864+
<PipeName condition="begin with">\postex_ssh_</PipeName>
865+
<PipeName condition="begin with">\status_</PipeName>
866+
<PipeName condition="begin with">\msagent_</PipeName>
867+
</PipeEvent>
868+
</RuleGroup>
857869

858870
<!--SYSMON EVENT ID 19 & 20 & 21 : WMI EVENT MONITORING [WmiEvent]-->
859871
<!--EVENT 19: "WmiEventFilter activity detected"-->

0 commit comments

Comments
 (0)