title: DN_0020_17_windows_sysmon_PipeEvent description: > This event generates when a named pipe is created. Malware often uses named pipes for interprocess communication loggingpolicy: - LP_0009_windows_sysmon_PipeEvent references: - https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-17.md - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90017 category: OS Logs platform: Windows type: Applications and Services Logs channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - Hostname # redundant - UtcTime - ProcessGuid - ProcessId - PipeName - Image sample: | - - 17 1 4 17 0 0x8000000000000000 46617 Microsoft-Windows-Sysmon/Operational atc-win-10.atc.local - 2019-02-05 13:37:34.396 {9683FBB1-919E-5C59-0000-0010A0E53B00} 7128 \PSEXESVC-ATC-WIN-7-2728-stdin C:\windows\PSEXESVC.exe