I think there might be an issue with Pipe Connection and Pipe Creation on the CrowdStrike field.
From reading the CrowdStrike docs, I can see that there is an eventfield called SmbClientNamedPipeConnectEtw:
"
An event that indicates when a machine connects to a remote SMB (Server Message Block) named pipe. The event contains the pattern id of the associated indicator and is supported on all Windows platform except 8.1 and Server 2012 R2. Captured using the ETW consumer.
"
CrowdStrike also has: NamedPipeDetectInfo which has the following NamedPipeOperationType which can be:
I think there might be an issue with Pipe Connection and Pipe Creation on the CrowdStrike field.
From reading the CrowdStrike docs, I can see that there is an eventfield called SmbClientNamedPipeConnectEtw: " An event that indicates when a machine connects to a remote SMB (Server Message Block) named pipe. The event contains the pattern id of the associated indicator and is supported on all Windows platform except 8.1 and Server 2012 R2. Captured using the ETW consumer. "
CrowdStrike also has: NamedPipeDetectInfo which has the following NamedPipeOperationType which can be: