<<< Hide Navigation Hide TOC >>>
PUA - RemCom Default Named Pipe (d36f87ea-c403-44d2-aa79-1a0ac7c24456)
Detects default RemCom pipe creation
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
SMB/Windows Admin Shares - T1021.002 (4f9ca633-15c5-463c-9724-bdcd54fde541) | Attack Pattern | PUA - RemCom Default Named Pipe (d36f87ea-c403-44d2-aa79-1a0ac7c24456) | Sigma-Rules | 1 |
Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) | Attack Pattern | PUA - RemCom Default Named Pipe (d36f87ea-c403-44d2-aa79-1a0ac7c24456) | Sigma-Rules | 1 |
Remote Services - T1021 (54a649ff-439a-41a4-9856-8d144a2551ba) | Attack Pattern | SMB/Windows Admin Shares - T1021.002 (4f9ca633-15c5-463c-9724-bdcd54fde541) | Attack Pattern | 2 |
System Services - T1569 (d157f9d2-d09a-4efa-bb2a-64963f94e253) | Attack Pattern | Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) | Attack Pattern | 2 |