Skip to content
Sysmon

Sysmon Event ID 18: Named pipe connected

PipeEvent (Pipe Connected)Sysmon event 18 logs a client connecting to a named pipe. Paired with event 17 it shows who talks over a pipe — useful for PsExec and C2 pivots.
18
Event ID
18
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 18 means

Sysmon event 18 records a process connecting to an existing named pipe. Together with event 17 (creation) it shows both ends of a pipe conversation.

When a pipe is reached over the network, the local connecting process is often System, because the SMB server handles the remote connection; in that case correlate with Security 5145 (share IPC$) to get the remote client. Local pipe connections show the real client process, which is how injected or spawned post-exploitation jobs talking back to their implant can surface.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <PipeEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeConnectPipe for this event.
ProcessGuidProcess that connected to the pipe.
ImageExecutable that connected. System usually means a connection that came in over SMB.
PipeNameName of the pipe.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Services and applications connecting to system pipes such as \lsass, \ntsvcs or \srvsvc.
  • Administrative tools connecting to PsExec or management pipes.

What attackers do that produces it

  • Connections to known C2 pipe names from an unexpected process.
  • Remote tools connecting to service-control or PsExec pipes during lateral movement.

Investigation tips

  • Match with event 17 on PipeName to identify the server process.
  • For System clients, look up Security 5145 on IPC$ with the same pipe to get the remote IP and account.

MITRE ATT&CK techniques

TechniqueTactics
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

17 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 6
  • High · 3
  • Medium · 7
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading