{"id":"T1559","name":"Inter-Process Communication","url":"https://attack.mitre.org/techniques/T1559","tactics":["execution"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0493","stix_id":"x-mitre-detection-strategy--b38e114c-f00f-4c70-9623-267da801625a","name":"Detect Abuse of Inter-Process Communication (T1559)","url":"https://attack.mitre.org/detectionstrategies/DET0493","analytics":[{"id":"AN1357","stix_id":"x-mitre-analytic--0c6a8e7a-f9d0-479a-88c1-4ce26edba81c","name":"Analytic 1357","description":"Detects anomalous use of COM, DDE, or named pipes for execution. Correlates creation or access of IPC mechanisms (e.g., named pipes, COM objects) with unusual parent-child process relationships or code injection patterns (e.g., Office spawning cmd.exe via DDE).","url":"https://attack.mitre.org/detectionstrategies/DET0493#AN1357","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=17","data_component":"DC0048","data_component_name":"Named Pipe Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"PipeNamePattern","description":"Environment-specific pipe names used legitimately vs anomalous (e.g., \\\\.\\pipe\\svcctl)."},{"field":"AllowedParentChildPairs","description":"Expected parent-child process lineage to minimize false positives (e.g., explorer.exe spawning outlook.exe)."}],"live":true,"detection_strategies":["DET0493"],"techniques":["T1559"]},{"id":"AN1358","stix_id":"x-mitre-analytic--ae8e028c-2c3a-4ac0-964f-d0b59533190d","name":"Analytic 1358","description":"Detects abuse of UNIX domain sockets, pipes, or message queues for unauthorized code execution. Correlates unexpected socket creation with suspicious binaries, abnormal shell pipelines, or injected processes establishing IPC channels.","url":"https://attack.mitre.org/detectionstrategies/DET0493#AN1358","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket: Suspicious creation of AF_UNIX sockets outside expected daemons","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open: Access to named pipes or FIFO in /tmp or /dev/shm by unexpected processes","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SocketPathBaseline","description":"Expected UNIX socket paths used by system services and applications."},{"field":"FIFOAccessPatterns","description":"Legitimate processes expected to open pipes in shared directories."}],"live":true,"detection_strategies":["DET0493"],"techniques":["T1559"]},{"id":"AN1359","stix_id":"x-mitre-analytic--3f42390d-2a44-4094-9cea-429f1286f8aa","name":"Analytic 1359","description":"Detects anomalous use of Mach ports, Apple Events, or XPC services for inter-process execution or code injection. Focuses on unexpected processes attempting to send privileged Apple Events (e.g., automation scripts injecting into security-sensitive apps).","url":"https://attack.mitre.org/detectionstrategies/DET0493#AN1359","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Unusual Mach port registration or access attempts between unrelated processes","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"exec: Unexpected execution of osascript or AppleScript targeting sensitive apps","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AllowedAppleEventTargets","description":"Whitelisted app-to-app Apple Event communications (e.g., Finder automation)."},{"field":"MachPortBaseline","description":"Baseline of Mach ports and XPC services normally used in the environment."}],"live":true,"detection_strategies":["DET0493"],"techniques":["T1559"]}],"live":true,"version":"1.0","techniques":["T1559"]}],"sigma_rules":[{"id":"58bf96d9-ff5f-44bd-8dcc-1c4f79bf3a27","title":"Trickbot Malware Activity","author":"Florian Roth (Nextron Systems)","status":"stable","level":"high","date":"2020-11-26","modified":"2021-11-27","description":"Detects Trickbot malware process tree pattern in which \"rundll32.exe\" is a parent of \"wermgr.exe\"","references":["https://twitter.com/swisscom_csirt/status/1331634525722521602?s=20","https://app.any.run/tasks/f74c5157-8508-4ac6-9805-d63fe7b0d399/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1559","detection.emerging-threats"],"path":"rules-emerging-threats/2020/Malware/Trickbot/proc_creation_win_malware_trickbot_wermgr.yml","techniques":["T1559"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}