• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Named Pipe Remote Access via JsonVMAccessExtension

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•2

    Detects named pipe activity with remote access enabled, initiated by JsonVMAccessExtension.exe running as SYSTEM. This may indicate abuse of the Azure VM Access Extension for unauthorized remote access.

    Microsoft Sentinel (KQL)

    Tags

    T1021 - Remote ServicesT1078.004 - Cloud AccountsTA0008 - Lateral MovementTA0005 - Defense EvasionTA0003 - PersistenceTA0004 - Privilege EscalationTA0001 - Initial AccessNamed Pipe CreationRemote Access SessionWindowsAzureWindows Defender Atpkql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?