Skip to content

Commit e2ea10c

Browse files
committed
headless_bee
1 parent 831743d commit e2ea10c

File tree

1 file changed

+1
-4
lines changed

1 file changed

+1
-4
lines changed

detections/endpoint/windows_anonymous_pipe_activity.yml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ data_source:
1010
- Sysmon EventID 17
1111
- Sysmon EventID 18
1212
search: '`sysmon` EventCode IN (17,18) EventType IN ( "CreatePipe", "ConnectPipe") PipeName="*Anonymous Pipe*" NOT( Image IN ("*\\Program Files\\*"))
13-
| stats min(_time) as firstTime max(_time) as lastTime count by dest user EventCode PipeName process_id process_guid Image EventType
13+
| stats min(_time) as firstTime max(_time) as lastTime count by dest EventCode PipeName ProcessGuid ProcessId Image EventType
1414
| `security_content_ctime(firstTime)`
1515
| `security_content_ctime(lastTime)`
1616
| `windows_anonymous_pipe_activity_filter`'
@@ -40,9 +40,6 @@ rba:
4040
- field: dest
4141
type: system
4242
score: 30
43-
- field: user
44-
type: user
45-
score: 30
4643
threat_objects: []
4744
tags:
4845
analytic_story:

0 commit comments

Comments
 (0)