name: Sysmon EventID 17 id: 08924246-c8e8-4c95-a9fc-633c43cc82df version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Sysmon EventID 17 logs details about the detection of a named pipe. mitre_components: - Named Pipe Metadata source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog separator: EventID separator_value: '17' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 version: 5.0.0 fields: - _time - Channel - Computer - EventChannel - EventCode - EventData_Xml - EventDescription - EventID - EventRecordID - EventType - Guid - Image - Keywords - Level - Name - Opcode - PipeName - ProcessGuid - ProcessID - ProcessId - RecordID - RecordNumber - RuleName - SecurityID - SystemTime - System_Props_Xml - Task - ThreadID - TimeCreated - UserID - UtcTime - Version - action - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dvc_nt_host - event_id - eventtype - host - id - index - linecount - os - pipe_name - process_exec - process_guid - process_id - process_name - process_path - punct - severity_id - signature - signature_id - source - sourcetype - splunk_server - tag - tag::eventtype - timeendpos - timestartpos - user_id - vendor_product output_fields: - dest - dvc - pipe_name - process_exec - process_guid - process_id - process_name - process_path - signature - signature_id - user_id - vendor_product example_log: 17141700x8000000000000000162168Microsoft-Windows-Sysmon/Operationalwin-dc-982.attackrange.local-CreatePipe2021-04-19 21:00:18.288{761B69BB-EF62-607D-B211-00000000BA01}6960\MSSE-1516-serverC:\Users\Administrator\Desktop\beacon.exe