Environment
EDR Sensor: Version 7.3.0 and Higher
Objective
How to locate named pipes for file creation events.
Resolution
- In the Console -> Process Search page, search recently executed processes for 'NamedPipeServer.exe' and/or 'NamedPipeClient.exe'
- Click on the process name and navigate to the Process Analysis page
- Locate the filemod create event for namedpipe under the 'NamedPipeServer.exe' entry (pipe name is : \device\namedpipe\cbnamedpipe)
Additional Notes
- The 7.3.0 EDR Sensor has been updated to report named pipes for file creation events.
Related Content