Inter-Process Communication

T1559

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize execution. IPC is also commonly used to avoid situations such as deadlocks, which occurs when processes are stuck in a cyclic waiting pattern.

Adversaries may abuse IPC to execute arbitrary code or commands. IPC mechanisms may differ depending on OS, but typically exists in a form accessible through programming languages/libraries or native interfaces such as Windows Dynamic Data Exchange or Component Object Model. Linux environments support several different IPC mechanisms, two of which being sockets and pipes. Higher level execution mediums, such as those of Command and Scripting Interpreters, may also leverage underlying IPC mechanisms. Adversaries may also use Remote Services such as Distributed Component Object Model to facilitate remote IPC execution.

Detection rules10

Rules on DetectionCode tagged with T1559 or one of its sub-techniques.

Sigma4

RuleLevelLog sourceTechnique
CMSTP Execution Process Accesshighwindows / process_accessT1559.001
DNS Query Request By Regsvr32.EXEmediumwindows / dns_queryT1559.001
Enable Microsoft Dynamic Data Exchangemediumwindows / registry_setT1559.002
Network Connection Initiated By Regsvr32.EXEmediumwindows / network_connectionT1559.001

Splunk6

RuleTypeRiskData sourceTechnique
Process Writing DynamicWrapperXHuntingNULLSysmon EventID 11T1559.001
Windows Anonymous Pipe ActivityHuntingNULLSysmon EventID 17, Sysmon EventID 18T1559
Windows PUA Named PipeAnomalyNULLSysmon EventID 17, Sysmon EventID 18T1559
Windows RMM Named PipeAnomalyNULLSysmon EventID 17, Sysmon EventID 18T1559
Windows Suspicious C2 Named PipeTTPNULLSysmon EventID 17, Sysmon EventID 18T1559
Windows Suspicious Named PipeTTPNULLSysmon EventID 17, Sysmon EventID 18T1559

Sub-techniques3

IDNameExamples
T1559.001Component Object Model22
T1559.002Dynamic Data Exchange20
T1559.003XPC Services0

Groups0

None recorded.

Software16

Campaigns2

Procedure examples18

Software16

Used byProcedure example
MalwareCyclops Blink

Cyclops Blink has the ability to create a pipe to enable inter-process communication.

MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

MalwareHyperStack

HyperStack can connect to the IPC$ share on remote machines.

MalwareLunarWeb

LunarWeb can retrieve output from arbitrary processes and shell commands via a pipe.

MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

MalwareMini Shai-Hulud

Mini Shai-Hulud has executed via the use of `subprocess.run` and fed input through standard input `stdin` which acted as a pipe to send data from the parent process and the child process `sys.executable` within memory.

MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

MalwareOilBooster

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

View all 16 software examples

Campaigns2

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

References2

  1. Fireeye Hunting COM June 2019 Open source
    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.
  2. Linux IPC Open source
    N/A. (2021, April 1). Inter Process Communication (IPC). Retrieved March 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.