This hunt targets adversaries leveraging C#-based red and black team tools that expose unique TypeLib GUIDs to establish a baseline of known security utilities within the environment. Proactively hunting for these artifacts in Azure Sentinel is essential to distinguish legitimate tooling from malicious C# payloads, ensuring low-severity signals are not overlooked during early-stage threat detection.
rule HKTL_NET_GUID_KeystrokeAPI {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/fabriciorissetto/KeystrokeAPI"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "f6fec17e-e22d-4149-a8a8-9f64c3c905d3" ascii nocase wide
$typelibguid1 = "b7aa4e23-39a4-49d5-859a-083c789bfea2" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypelibGUID rule in an enterprise environment, along with suggested filters:
Scenario: Automated Compliance Scanning by Microsoft Endpoint Configuration Manager (MECM/SCCM)
ccmexec.exe) frequently launches C# inventory agents to scan hardware and software configurations. These agents often instantiate standard .NET libraries that share the same TypelibGUID signatures as known red-team tools like Cobalt Strike or SharpUp, even though they are performing routine asset discovery rather than adversarial reconnaissance.C:\Program Files\Microsoft Configuration Manager\Client\ccmexec.exe and its child processes when the parent is svchost.exe (Service Host). Additionally, exclude specific TypelibGUID values associated with the .NET Framework version installed on your SCCM servers if they match the rule’s signature.Scenario: Scheduled PowerShell Health Checks using the Microsoft Management Console (MMC)
TypelibGUID events identical to those used by blue-team forensic tools (e.g., Sysmon configuration modules), triggering the rule during non-business hours.mmc.exe or powershell.exe running under a specific service account (e.g., DOMAIN\svc-ad-healthcheck) and occurring within the defined maintenance window (e.g., 02:00 – 04:00 UTC).**Scenario: Deployment of Visual Studio Build Agents on CI/CD Pip