Cobalt Strike / Metasploit Suspicious Named Pipe Creation
Detects the creation of named pipes with names frequently associated with common post-exploitation tools, such as Cobalt Strike. The rule filters out common browser processes and critical Windows system processes to reduce noise.
SentinelOne

