Date: Sep 17, 2024, 05:06 AM Host: Shepherd (172[.]16[.]17[.]128) Severity: High | Outcome: True Positive
Named pipe token impersonation attack chain on host Shepherd. Attacker brute forced the LetsDefend local account, attempted privilege escalation via runas, then constructed a named pipe (\\.\pipe\TestSVC) to capture a SYSTEM-level token. The Empire Get-System module was fetched directly into memory via IEX/IWR over TLS — no payload written to disk, evading EDR detection entirely.
| Event | Timestamp |
|---|---|
| Brute force activity | Prior to 05:06 AM |
| Alert triggered | Sep 17, 2024, 05:06 AM |
| Field | Value |
|---|---|
| Hostname | Shepherd |
| Internal IP | 172[.]16[.]17[.]128 |
| Attacker IP | 146[.]70[.]202[.]86 |
External attacker operating from 146[.]70[.]202[.]86. Post-brute-force execution occurred under the LetsDefend user context.
Attacker sought SYSTEM-level access after gaining an unprivileged foothold. runas failed to elevate privileges, leading the attacker to use Empire’s named pipe impersonation technique. Fileless in-memory execution via IEX/IWR bypassed EDR.
| Stage | Action |
|---|---|
| Initial Access | Brute force from 146[.]70[.]202[.]86 → LetsDefend account compromised |
| Privilege Escalation Attempt | runas /user:LetsDefend "powershell.exe" — no additional privilege gained |
| Named Pipe Setup | cmd.exe spawns pipe client: echo TestSVC > \\.\pipe\TestSVC with 3s delay |
| Token Impersonation | Get-System -Technique NamedPipe captures SYSTEM token via ImpersonateNamedPipeClient() |
| Fileless Execution | Empire module loaded into memory via IEX (IWR '...') over TLS 1.2 |
Forensic note: No TestSVC process artifact recovered from endpoint process list. Only the spawning PowerShell process was visible. Consistent with transient named pipe interaction and in-memory execution — no persistent process or file artifact created.
| Technique ID | Tactic | Technique |
|---|---|---|
| T1110 | Credential Access | Brute Force |
| T1134.001 | Privilege Escalation | Access Token Manipulation: Token Impersonation/Theft |
| T1059.001 | Execution | Command and Scripting Interpreter: PowerShell |
| T1105 | Command and Control | Ingress Tool Transfer |
| T1620 | Defense Evasion | Reflective Code Loading |
| Type | Value |
|---|---|
| Attacker IP | 146[.]70[.]202[.]86 |
| Target IP | 172[.]16[.]17[.]128 |
| Hostname | Shepherd |
| User Account | LetsDefend |
| Named Pipe | \\.\pipe\TestSVC |
| Script URL | hxxps[://]raw[.]githubusercontent[.]com/BC-SECURITY/Empire/f6efd5a963d424a1f983d884b637da868e5df466/data/module_source/privesc/Get-System[.]ps1 |
| Process | C:\Windows\System32\runas[.]exe |
| Process | C:\Windows\System32\cmd[.]exe |
| EventID | 4104 (PowerShell script block), 4688 (process creation) |
| EDR Action | Not Detected |
🔬 Analysis Reports 🦠 VirusTotal https://www.abuseipdb.com/check/146.70.202.86?page=4