Event ID 9007006 — Named pipe event
Description
Named pipe event
Fields #
| Name | Description |
|---|---|
DeviceId | — |
Timestamp | — |
FileName | — |
InitiatingProcessFileName | — |
Detection Patterns #
Named Pipe
Defender-DeviceEvents Event ID 9007006: Named pipe eventORSysmon Event ID 17: PipeEventOREvent ID 18: PipeEvent
15 rules
Sigma
Splunk
Show 3 more (6 total)
Kusto Query Language
References #
- Microsoft Defender XDR — advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceevents-table