Suspicious Named Pipe Creation by Non-System Process - C2/Post-Exploitation

This rule detects the creation of named pipes associated with known command-and-control (C2) frameworks, post-exploitation toolkits, and suspicious system activity. By filtering out common legitimate system processes and monitoring for specific pipe patterns (e.g., Cobalt Strike, Metasploit, PsExec, and sensitive RPC endpoints), the rule identifies potential lateral movement, remote execution, and post-exploitation communication channels.