Replies: 1 comment
-
@rroupski have we determined the next steps here? |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
With that said, named Pipes events to have multiple unique fields (ENUMs) that aren`t relevant to the existing file events but that are needed for threat hunting/analysis. For example:
For more info see https://learn.microsoft.com/en-us/windows/win32/api/winbase/nf-winbase-createnamedpipea
With the above in mind, it might be worth having a dedicated class for Named Pipes.
0 votes ·
Beta Was this translation helpful? Give feedback.
All reactions