LoFP LoFP / t1055

t1055

TitleTags
\pipe\local\monitorian
a newly installed program or one that rarely uses the network could trigger this alert.
administrative scripts
changes to windows services or a rarely executed child process.
chrome instances using the exact same pipe name \"mojo.xxx\"
controlled red-team, malware-analysis, detection-validation, or harness activity where script content, target process set, origin, user/host scope, and recovered launcher align.
debugging or legitimate software testing
legitimate use of msra.exe
printing documents via notepad might cause communication with the printer via port 9100 or similar.
rpcnet.exe / rpcnetp.exe which is a lojack style software. https://www.blackhat.com/docs/us-14/materials/us-14-kamlyuk-kamluk-computrace-backdoor-revisited.pdf
the build engine is commonly used by windows developers but use by non-engineers is unusual.
this rule is best put in testing first in order to create a baseline that reflects the data in your environment.
unknown
unlikely
websense endpoint using the pipe name \"dsernamepipe(r|w)\d{1,5}\"