Skip to content

Conversation

@RavenTait
Copy link
Contributor

@RavenTait RavenTait commented Dec 4, 2025

Details

New Analytic Story:

  • Tuoni

New Analytics

  • Windows PUA Named Pipe
  • Windows RMM Named Pipe
  • Windows Suspicious C2 Named Pipe
  • Windows Suspicious Named Pipe

New Lookups

  • pua_named_pipes
  • suspicious_c2_named_pipes
  • suspicious_named_pipes
  • suspicious_rmm_named_pipes

Breaking Changes

  • Deprectated Cobalt Strike Named Pipes analytic as it's now included in this larger collection of pipe names.

Copy link
Contributor

@nasbench nasbench left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall LGTM. But I highly suggest we split the pipe csv into different categories.

Based on the type column you have, I can suggest C2, RMM, PUA (for stuff like PsExec, Dotnet)

That way it'll be easier to manage FPs and RBA / Findings would not blow up.

The C2 category can be TTP and the rest can be anomaly with a much lower risk score.

Copy link
Contributor

@nasbench nasbench left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nasbench nasbench added this to the v5.19.0 milestone Dec 8, 2025
@nasbench nasbench merged commit 6032db5 into develop Dec 8, 2025
4 checks passed
@nasbench nasbench deleted the tuoni_and_more branch December 8, 2025 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants