Suspicious Named Pipe Creation by Non-System Process (C2 Frameworks)
Detects the creation of named pipes with names commonly utilized by offensive C2 frameworks such as Cobalt Strike, Metasploit, and Covenant. By monitoring for specific pipe naming patterns created by non-system processes, this rule aims to identify potential post-exploitation activity, C2 beacons, or lateral movement tools.
Microsoft Sentinel (KQL)

