Most Important Detection 2026: Cobalt Strike/Sliver Beacon Named Pipe C2

This rule detects potential command-and-control (C2) activity by correlating the creation of known Cobalt Strike or Sliver framework named pipes with subsequent repeated HTTP/S network beaconing from the same process or host. The rule identifies processes establishing suspicious named pipes, then looks for persistent network connections to standard web ports (80, 443) within a 30-minute window, flagging instances where significant beaconing count is observed.