communication/named-pipe/create
rule:
meta:
name: create two anonymous pipes
namespace: communication/named-pipe/create
authors:
- matthew.williams@mandiant.com
scopes:
static: function
dynamic: thread
mbc:
- Communication::Interprocess Communication::Create Pipe [C0003.001]
examples:
- Practical Malware Analysis Lab 14-02.exe_:0x4011C0
features:
- and:
- count(api(CreatePipe)): 2
last edited: 2023-11-24 10:34:28