You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'll add the msagent_ named pipe, but I am unsure about the status_ named pipe. My guess is that it would cause many false positives if it gets implemented as status_*.
Addition to sysmon_mal_namedpipes.yml:
CS default named pipes:
msagent_#number used by SMB Beacon's peer-to-peer communication.
status_#number used by SMB Beacon's named pipe stager
Ref:
https://blog.cobaltstrike.com/2019/02/19/cobalt-strike-team-server-population-study/
https://www.cobaltstrike.com/help-malleable-c2
The text was updated successfully, but these errors were encountered: