Privilege Escalation via Named Pipe Impersonation — Detection Rule

Detects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.

Read the full analysis on IntelFusions