# Feature Request: Native named pipe events in Elastic Defend (SMB beacon detection)

**URL:** <https://discuss.elastic.co/t/feature-request-native-named-pipe-events-in-elastic-defend-smb-beacon-detection/386595>\
**Category:** Elastic Security\
**Created:** [May 31, 2026, 8:56pm UTC](https://discuss.elastic.co/t/feature-request-native-named-pipe-events-in-elastic-defend-smb-beacon-detection/386595 "2026-05-31T20:56:05Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![labrend](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/labrend/32/147614_2.png) [@labrend](https://discuss.elastic.co/u/labrend)\
**Post date:** [May 31, 2026, 8:56pm UTC](https://discuss.elastic.co/t/feature-request-native-named-pipe-events-in-elastic-defend-smb-beacon-detection/386595/1 "2026-05-31T20:56:06Z")

</div>

Hi everyone,

I've just submitted a feature request on GitHub to add native named pipe event collection to Elastic Defend:

[[Elastic Defend] Add native named pipe event collection (Sysmon EID 17/18 equivalent) · Issue #272056 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/272056)

## Problem

Elastic Defend currently cannot detect SMB bind beacons (Cobalt Strike, Havoc, Metasploit) because it does not collect named pipe creation/connection events natively.

SMB beacons operate exclusively through named pipes - no outbound network connections, which makes them invisible to network-based detection.

Currently the only workaround is Sysmon EID 17/18 , which requires maintaining a separate agent alongside Elastic Agent.

## Request

Add pipe\_created / pipe\_connected events to Elastic Defend telemetry - equivalent to Sysmon EID 17 and 18.

This would enable detection of:

- Cobalt Strike SMB beacons (\.\pipe\msagent\ __, postex\__ )
- Lateral movement via named pipes (PsExec pattern)
- Privilege escalation via named pipe impersonation (T1134.001)

This diagram shows a real-world Adaptix C2 scenario where an SMB bind beacon (p0) communicates laterally to a Domain Controller exclusively via named pipes - completely invisible without Sysmon EID 17/18 or native Elastic Defend pipe event collection.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7edf86efb1a2b47360a20c92df5da99e10f59f50.jpeg)

And allow existing prebuilt rules to work WITHOUT Sysmon:

- "Privilege Escalation via Rogue Named Pipe Impersonation"

## Ask

If this is important to you - please 👍 the GitHub issue and comment with your use case. More votes = higher priority!

Thanks
