Sysmon Event ID 17: Named pipe created
- Event ID
- 17
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 17 means
Sysmon event 17 records the server side of a named pipe: the process that created it and the PipeName. Named pipes are a standard Windows IPC mechanism and are also reachable over SMB, which makes them popular with remote-administration and C2 tools.
Many tools use recognizable default names: PsExec creates \PSEXESVC, and several post-exploitation frameworks use default patterns such as \MSSE-<number>-server or \postex_<id> in Cobalt Strike. Operators can change these, so pipe names are strong when they match and weak when they do not.
When it is logged
Sysmon installed; filter with <PipeEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | CreatePipe for this event. |
| ProcessGuid | Process that created the pipe. |
| Image | Executable that created the pipe. |
| PipeName | Name of the pipe, e.g. \PSEXESVC. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- System services, browsers (Chrome/Edge
\mojo.*pipes) and SQL Server creating pipes constantly. - Legitimate PsExec use by administrators.
What attackers do that produces it
- Default C2 pipe names such as
\MSSE-*-serveror\postex_*created by an unexpected process. PSEXESVCor a random service pipe created right after a remote service install (System 7045).
Investigation tips
- Match PipeName against known tool defaults and rare names across the fleet.
- Pivot on ProcessGuid to event 1; pipes created by
rundll32.exeor processes from temp folders are suspicious. - Look for event 18 showing which process connected to the pipe.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
17 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 6
- High · 3
- Medium · 7
- Info · 1
- CriticalCobaltStrike Named PipeRule by Florian Roth (Nextron Systems), Wojciech Lesicki, SigmaHQ, DRL 1.1
- CriticalCobaltStrike Named Pipe Pattern RegexRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Credential Dumping Tools Named Pipe CreatedRule by Teymur Kheirkhabarov, oscd.community, SigmaHQ, DRL 1.1
- CriticalHackTool - DiagTrackEoP Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Koh Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalMalicious Named Pipe CreatedRule by Florian Roth (Nextron Systems), blueteam0ps, elhoim, SigmaHQ, DRL 1.1
- HighCobaltStrike Named Pipe PatternsRule by Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - CoercedPotato Named Pipe CreationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - EfsPotato Named Pipe CreationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumADFS Database Named Pipe Connection By Uncommon ToolRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumAlternate PowerShell Hosts PipeRule by Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, SigmaHQ, DRL 1.1
- MediumPsExec Tool Execution From Suspicious Locations - PipeNameRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - CSExec Default Named PipeRule by Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - PAExec Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - RemCom Default Named PipeRule by Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumWMI Event Consumer Created Named PipeRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- InfoNew PowerShell Instance CreatedRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.