Skip to content

Commit d3dbadd

Browse files
committed
suspicious WMI Event Consumer creates named pipe
1 parent 5c2fdc2 commit d3dbadd

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

sysmonconfig-export.xml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -958,6 +958,7 @@
958958
<PipeName condition="begin with">\wkssvc</PipeName>
959959
<!-- Other specific named pipes -->
960960
<PipeName condition="contains">6e7645c4-32c5-4fe3-aabf-e94c2f4370e7</PipeName> <!-- LiquidSnake hacktool https://github.com/RiccardoAncarani/LiquidSnake -->
961+
<Image condition="end with">\scrcons.exe</Image> <!-- Susupicious WMI Event Consumer creating a named pipe -->
961962
</PipeEvent>
962963
</RuleGroup>
963964
<!-- we skip the connect pipe event since they could be to noisy and a CreatePipe event should come before these -->

0 commit comments

Comments
 (0)