// soc investigation 2026-07-06
SOC322 Named Pipe Token Impersonation Detected
letsdefend High ✓ true positive
mitre/T1110Mitre/T1134-001mitre/T1059-001mitre/T1105
analyst verdict TRUE POSITIVE
✓

IR Case — SOC322 Named Pipe Token Impersonation

Date: Sep 17, 2024, 05:06 AM Host: Shepherd (172[.]16[.]17[.]128) Severity: High | Outcome: True Positive


What

Named pipe token impersonation attack chain on host Shepherd. Attacker brute forced the LetsDefend local account, attempted privilege escalation via runas, then constructed a named pipe (\\.\pipe\TestSVC) to capture a SYSTEM-level token. The Empire Get-System module was fetched directly into memory via IEX/IWR over TLS — no payload written to disk, evading EDR detection entirely.


When

EventTimestamp
Brute force activityPrior to 05:06 AM
Alert triggeredSep 17, 2024, 05:06 AM

Where

FieldValue
HostnameShepherd
Internal IP172[.]16[.]17[.]128
Attacker IP146[.]70[.]202[.]86

Who

External attacker operating from 146[.]70[.]202[.]86. Post-brute-force execution occurred under the LetsDefend user context.


Why

Attacker sought SYSTEM-level access after gaining an unprivileged foothold. runas failed to elevate privileges, leading the attacker to use Empire’s named pipe impersonation technique. Fileless in-memory execution via IEX/IWR bypassed EDR.


Attack Chain

StageAction
Initial AccessBrute force from 146[.]70[.]202[.]86 → LetsDefend account compromised
Privilege Escalation Attemptrunas /user:LetsDefend "powershell.exe" — no additional privilege gained
Named Pipe Setupcmd.exe spawns pipe client: echo TestSVC > \\.\pipe\TestSVC with 3s delay
Token ImpersonationGet-System -Technique NamedPipe captures SYSTEM token via ImpersonateNamedPipeClient()
Fileless ExecutionEmpire module loaded into memory via IEX (IWR '...') over TLS 1.2

Forensic note: No TestSVC process artifact recovered from endpoint process list. Only the spawning PowerShell process was visible. Consistent with transient named pipe interaction and in-memory execution — no persistent process or file artifact created.


MITRE ATT&CK

Technique IDTacticTechnique
T1110Credential AccessBrute Force
T1134.001Privilege EscalationAccess Token Manipulation: Token Impersonation/Theft
T1059.001ExecutionCommand and Scripting Interpreter: PowerShell
T1105Command and ControlIngress Tool Transfer
T1620Defense EvasionReflective Code Loading

IOCs

TypeValue
Attacker IP146[.]70[.]202[.]86
Target IP172[.]16[.]17[.]128
HostnameShepherd
User AccountLetsDefend
Named Pipe\\.\pipe\TestSVC
Script URLhxxps[://]raw[.]githubusercontent[.]com/BC-SECURITY/Empire/f6efd5a963d424a1f983d884b637da868e5df466/data/module_source/privesc/Get-System[.]ps1
ProcessC:\Windows\System32\runas[.]exe
ProcessC:\Windows\System32\cmd[.]exe
EventID4104 (PowerShell script block), 4688 (process creation)
EDR ActionNot Detected

🔬 Analysis Reports 🦠 VirusTotal https://www.abuseipdb.com/check/146.70.202.86?page=4

https://raw.githubusercontent.com/BC-SECURITY/Empire/f6efd5a963d424a1f983d884b637da868e5df466/data/module_source/privesc/Get-System.ps1