Contextual data about a named pipe on a system, including pipe name and creating process (ex: Sysmon EIDs 17-18)
Data Collection Measures:
mkfifo, open, read, write syscalls): Tracks FIFO (named pipe) creation and usage.lsof -p <PID> or lsof | grep PIPE): Lists active named pipes and associated processes.strace -e open <process>): Monitors named pipe interactions.pipescan): Enumerates named pipes in system memory.| Name | Channel |
|---|---|
| macos:unifiedlog | XPC messages requesting privileged actions from untrusted or unsigned clients |
| WinEventLog:Sysmon | EventCode=17 |