auditing-windows-named-pipe-and-rpc-exposure - Audit Windows named pipe, RPC, and COM exposures
Audits Windows services exposing named pipes, RPC endpoints, or COM servers to low-privileged callers without proper authorization checks.
Tags
Updated: 2026-09-22Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Enumerate service inter-process interfaces
- Inspect interface access permissions
- Map reachable operations to actions
- Check caller operation authorization
- Evaluate client impersonation safety
- Record findings or kill reasons
Inputs
- Windows inter-process interfaces
- Interface access control lists
- Caller-supplied operation parameters
- Lower-privileged caller context
Outputs
- Audit record with findings details
- Benign proof of driven behavior
- Kill reason for safe interfaces
Requirements
- Authorized Windows host or snapshot
- Isolated testing environment
