IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How To Detect Named Pipes for File Creation Events

EDR: How To Detect Named Pipes for File Creation Events

Environment

EDR Sensor: Version 7.3.0 and Higher

Objective

How to locate named pipes for file creation events.
 

Resolution

  1. In the Console -> Process Search page, search recently executed processes for 'NamedPipeServer.exe' and/or 'NamedPipeClient.exe'
  2. Click on the process name and navigate to the Process Analysis page
  3. Locate the filemod create event for namedpipe under the 'NamedPipeServer.exe' entry (pipe name is : \device\namedpipe\cbnamedpipe)

Additional Notes

  • The 7.3.0 EDR Sensor has been updated to report named pipes for file creation events.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎04-27-2022
Views:
1161
Contributors