Important and relevant NamedPipe names#151
Important and relevant NamedPipe names#151SwiftOnSecurity merged 2 commits intoSwiftOnSecurity:masterfrom Neo23x0:patch-8
Conversation
The events generated by an explicit matches on the listed pipe names should be few and highly relevant.
|
Hi @Neo23x0, I think your proposition is better because it is more universal. I, on the other hand, focused on Cobalt Strike. |
|
@WojciechLesicki : Oh, I haven't noticed your PR. I've added the missing pipe and also added some comments. |
|
Looks like there may be a typo - psexec, no? EDIT: Any reason why psexec is not listed as well? |
|
No, Psexec may cause too many FPs. I intentionally tried to include only pipes that indicate unwanted or malicious behaviour. |
|
Ping |
|
Only as a reference - today similar PR from me was merged on @olafhartong repo: As @Neo23x0 mentioned - we need this also here :) |
The events generated by an explicit matches on the listed pipe names should be few and highly relevant.