EXPLORE
← Back to Explore
sigmahighHunting

First Time Seen Remote Named Pipe - Zeek

This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes

MITRE ATT&CK

lateral-movement

Detection Query

selection:
  path: \\\\\*\\IPC$
filter_keywords:
  - samr
  - lsarpc
  - winreg
  - netlogon
  - srvsvc
  - protected_storage
  - wkssvc
  - browser
  - netdfs
  - svcctl
  - spoolss
  - ntsvcs
  - LSM_API_service
  - HydraLsPipe
  - TermSrv_API_service
  - MsFteWds
condition: selection and not 1 of filter_*

Author

Samir Bousseaden, @neu5ron, Tim Shelton

Created

2020-04-02

Data Sources

zeeksmb_files

Platforms

zeek

Tags

attack.lateral-movementattack.t1021.002
Raw Content
title: First Time Seen Remote Named Pipe - Zeek
id: 021310d9-30a6-480a-84b7-eaa69aeb92bb
related:
    - id: 52d8b0c6-53d6-439a-9e41-52ad442ad9ad
      type: derived
status: test
description: This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
references:
    - https://twitter.com/menasec1/status/1104489274387451904
author: Samir Bousseaden, @neu5ron, Tim Shelton
date: 2020-04-02
modified: 2022-12-27
tags:
    - attack.lateral-movement
    - attack.t1021.002
logsource:
    product: zeek
    service: smb_files
detection:
    selection:
        path: '\\\\\*\\IPC$' # Looking for the string \\*\IPC$
    filter_keywords:
        - 'samr'
        - 'lsarpc'
        - 'winreg'
        - 'netlogon'
        - 'srvsvc'
        - 'protected_storage'
        - 'wkssvc'
        - 'browser'
        - 'netdfs'
        - 'svcctl'
        - 'spoolss'
        - 'ntsvcs'
        - 'LSM_API_service'
        - 'HydraLsPipe'
        - 'TermSrv_API_service'
        - 'MsFteWds'
    condition: selection and not 1 of filter_*
falsepositives:
    - Update the excluded named pipe to filter out any newly observed legit named pipe
level: high