This rule detects adversary behavior where threat actors utilize C#-based red and black team tools that register unique TypeLibGUID identifiers within the Windows Registry to establish persistence or execute reconnaissance tasks. The SOC team should proactively hunt for these specific GUIDs in Azure Sentinel to distinguish legitimate security tooling from malicious implants, ensuring early identification of advanced persistent threats leveraging custom .NET frameworks.
rule HKTL_NET_GUID_Ladon {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/k8gege/Ladon"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "c335405f-5df2-4c7d-9b53-d65adfbed412" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypelibGUID rule, tailored for an enterprise environment:
Scenario: Automated Patch Management Deployment
TypelibGUIDs when scanning inventory, installing patches, or running compliance checks on endpoints. Since these are standard administrative operations occurring across thousands of machines, they generate high-volume noise identical to red-team tool execution.ccmexec.exe, CcmExec.exe, or specific Intune agent processes) and restrict the alert logic to only trigger if the parent process is not a known system service. Alternatively, whitelist the specific TypelibGUID values known to belong to the SCCM/Intune agents in your environment’s asset inventory.Scenario: Scheduled Backup and Data Integrity Checks
TypelibGUIDs outside of business hours (e.g., 08:00–17:00) if the backup jobs are known to run at night. Additionally, add an exclusion rule based on the file path of the executable (e.g.,