File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 967967 <!-- Other specific named pipes -->
968968 <PipeName condition =" contains" >6e7645c4-32c5-4fe3-aabf-e94c2f4370e7</PipeName > <!-- LiquidSnake hacktool https://github.com/RiccardoAncarani/LiquidSnake -->
969969 <Image condition =" end with" >\scrcons.exe</Image > <!-- Susupicious WMI Event Consumer creating a named pipe -->
970- </PipeEvent >
971- <!-- Some interesting ConnectPipe events that we want to include -->
972- <PipeEvent onmatch =" include" >
973- <EventType condition =" is" >ConnectPipe</EventType >
974- <PipeName condition =" is" >\MICROSOFT##WID\tsql\query</PipeName > <!-- https://github.com/SigmaHQ/sigma/pull/2128 -->
970+ <Rule groupRelation =" and" > <!-- Some interesting ConnectPipe events that we want to include -->
971+ <EventType condition =" is" >ConnectPipe</EventType >
972+ <PipeName condition =" is" >\MICROSOFT##WID\tsql\query</PipeName > <!-- https://github.com/SigmaHQ/sigma/pull/2128 -->
973+ </Rule >
975974 </PipeEvent >
976975 </RuleGroup >
977976 <!-- Common Pipe Names to would appear very often in -->
You can’t perform that action at this time.
0 commit comments