Loading...
Windows Events

Pipe Connected

Event ID 18 Microsoft-Windows-Sysmon/Operational Sysmon/Pipe Connected

Main fields

IP address
IP
Windows IP
ELK -
Microsoft Sentinel -
QRadar -
Splunk -
Computer name
Computer
Windows Computer
ELK winlog.computer_name
Microsoft Sentinel -
QRadar -
Splunk -
User name
User
Windows User
ELK winlog.event_data.User
Microsoft Sentinel -
QRadar -
Splunk -
Important field
PipeName
Windows PipeName
ELK winlog.event_data.PipeName
Microsoft Sentinel -
QRadar -
Splunk -

Fields

Windows Raw Windows ELK Microsoft Sentinel QRadar Splunk
RuleName RuleName winlog.event_data.RuleName - - -
EventType EventType winlog.event_data.EventType - - -
ProcessGuid ProcessGuid winlog.event_data.ProcessGuid - - -
ProcessId ProcessId winlog.event_data.ProcessId - - -
PipeName PipeName winlog.event_data.PipeName - - -
Image Image winlog.event_data.Image - - -
User User winlog.event_data.User - - -
IP System field IP System field - - - -
Computer System field Computer System field winlog.computer_name - - -
ProcessID System field ProcessID System field winlog.process.pid - - -
ThreadID System field ThreadID System field winlog.process.thread.id - - -

Sample Event

- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Sysmon" Guid="{5770385f-c22a-43e0-bf4c-06f5698ffbd9}" /> 
  <EventID>18</EventID> 
  <Version>1</Version> 
  <Level>4</Level> 
  <Task>18</Task> 
  <Opcode>0</Opcode> 
  <Keywords>0x8000000000000000</Keywords> 
  <TimeCreated SystemTime="2026-08-02T14:45:56.2530240Z" /> 
  <EventRecordID>95963</EventRecordID> 
  <Correlation /> 
  <Execution ProcessID="6656" ThreadID="7772" /> 
  <Channel>Microsoft-Windows-Sysmon/Operational</Channel> 
  <Computer>ADCS.socpedia.net</Computer> 
  <Security UserID="S-1-5-18" /> 
  </System>
- <EventData>
  <Data Name="RuleName">v1-0_eventID17,18</Data> 
  <Data Name="EventType">ConnectPipe</Data> 
  <Data Name="UtcTime">2026-08-02 14:45:56.252</Data> 
  <Data Name="ProcessGuid">{e4c645e2-94a9-6a67-eb03-000000000000}</Data> 
  <Data Name="ProcessId">4</Data> 
  <Data Name="PipeName">\cert</Data> 
  <Data Name="Image">System</Data> 
  <Data Name="User">NT AUTHORITY\SYSTEM</Data> 
  </EventData>
  </Event>

SOCpedia - knowledge platform

This section contains materials on SOC and Blue Team practices: articles, news, books, and translations.