DC0048 Named Pipe Metadata
| Item | Value |
|---|---|
| ID | DC0048 |
| Version | 2.0 |
| Created | 20 October 2021 |
| Last Modified | 21 October 2025 |
Log Sources
| Name | Channel |
|---|---|
| macos:unifiedlog | XPC messages requesting privileged actions from untrusted or unsigned clients |
| WinEventLog:Sysmon | EventCode=17 |
Detection Strategy
| ID | Name | Technique Detected |
|---|---|---|
| DET0182 | Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS | T1135 |
| DET0389 | Behavioral Detection of DLL Injection via Windows API | T1055.001 |
| DET0493 | Detect Abuse of Inter-Process Communication (T1559) | T1559 |
| DET0335 | Detect Abuse of XPC Services (T1559.003) | T1559.003 |