Skip to content

DC0048 Named Pipe Metadata

Item Value
ID DC0048
Version 2.0
Created 20 October 2021
Last Modified 21 October 2025

Log Sources

Name Channel
macos:unifiedlog XPC messages requesting privileged actions from untrusted or unsigned clients
WinEventLog:Sysmon EventCode=17

Detection Strategy

ID Name Technique Detected
DET0182 Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS T1135
DET0389 Behavioral Detection of DLL Injection via Windows API T1055.001
DET0493 Detect Abuse of Inter-Process Communication (T1559) T1559
DET0335 Detect Abuse of XPC Services (T1559.003) T1559.003