Skip to content
Sysmon

Sysmon Event ID 17: Named pipe created

PipeEvent (Pipe Created)Sysmon event 17 logs a named pipe being created and the process behind it. Known pipe names reveal PsExec, C2 frameworks and other lateral movement tools.
17
Event ID
17
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 17 means

Sysmon event 17 records the server side of a named pipe: the process that created it and the PipeName. Named pipes are a standard Windows IPC mechanism and are also reachable over SMB, which makes them popular with remote-administration and C2 tools.

Many tools use recognizable default names: PsExec creates \PSEXESVC, and several post-exploitation frameworks use default patterns such as \MSSE-<number>-server or \postex_<id> in Cobalt Strike. Operators can change these, so pipe names are strong when they match and weak when they do not.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <PipeEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeCreatePipe for this event.
ProcessGuidProcess that created the pipe.
ImageExecutable that created the pipe.
PipeNameName of the pipe, e.g. \PSEXESVC.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • System services, browsers (Chrome/Edge \mojo.* pipes) and SQL Server creating pipes constantly.
  • Legitimate PsExec use by administrators.

What attackers do that produces it

  • Default C2 pipe names such as \MSSE-*-server or \postex_* created by an unexpected process.
  • PSEXESVC or a random service pipe created right after a remote service install (System 7045).

Investigation tips

  • Match PipeName against known tool defaults and rare names across the fleet.
  • Pivot on ProcessGuid to event 1; pipes created by rundll32.exe or processes from temp folders are suspicious.
  • Look for event 18 showing which process connected to the pipe.

MITRE ATT&CK techniques

TechniqueTactics
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement
T1569.002 System Services: Service ExecutionExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

17 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 6
  • High · 3
  • Medium · 7
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading