Sysmon Event ID 18: Named pipe connected
- Event ID
- 18
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 18 means
Sysmon event 18 records a process connecting to an existing named pipe. Together with event 17 (creation) it shows both ends of a pipe conversation.
When a pipe is reached over the network, the local connecting process is often System, because the SMB server handles the remote connection; in that case correlate with Security 5145 (share IPC$) to get the remote client. Local pipe connections show the real client process, which is how injected or spawned post-exploitation jobs talking back to their implant can surface.
When it is logged
Sysmon installed; filter with <PipeEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | ConnectPipe for this event. |
| ProcessGuid | Process that connected to the pipe. |
| Image | Executable that connected. System usually means a connection that came in over SMB. |
| PipeName | Name of the pipe. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Services and applications connecting to system pipes such as
\lsass,\ntsvcsor\srvsvc. - Administrative tools connecting to PsExec or management pipes.
What attackers do that produces it
- Connections to known C2 pipe names from an unexpected process.
- Remote tools connecting to service-control or PsExec pipes during lateral movement.
Investigation tips
- Match with event 17 on PipeName to identify the server process.
- For
Systemclients, look up Security 5145 onIPC$with the same pipe to get the remote IP and account.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1021.002 Remote Services: SMB/Windows Admin Shares | Lateral Movement |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
17 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 6
- High · 3
- Medium · 7
- Info · 1
- CriticalCobaltStrike Named PipeRule by Florian Roth (Nextron Systems), Wojciech Lesicki, SigmaHQ, DRL 1.1
- CriticalCobaltStrike Named Pipe Pattern RegexRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Credential Dumping Tools Named Pipe CreatedRule by Teymur Kheirkhabarov, oscd.community, SigmaHQ, DRL 1.1
- CriticalHackTool - DiagTrackEoP Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Koh Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalMalicious Named Pipe CreatedRule by Florian Roth (Nextron Systems), blueteam0ps, elhoim, SigmaHQ, DRL 1.1
- HighCobaltStrike Named Pipe PatternsRule by Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - CoercedPotato Named Pipe CreationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - EfsPotato Named Pipe CreationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumADFS Database Named Pipe Connection By Uncommon ToolRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- MediumAlternate PowerShell Hosts PipeRule by Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, SigmaHQ, DRL 1.1
- MediumPsExec Tool Execution From Suspicious Locations - PipeNameRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - CSExec Default Named PipeRule by Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - PAExec Default Named PipeRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPUA - RemCom Default Named PipeRule by Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumWMI Event Consumer Created Named PipeRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- InfoNew PowerShell Instance CreatedRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.