This hunt hypothesis posits that adversaries are deploying C#-based red and black team tools within the environment to establish persistence or conduct reconnaissance, identifiable by unique TypeLibGUID artifacts in process execution logs. Proactively hunting for these specific GUIDs in Azure Sentinel is critical because they often indicate legitimate security tooling masquerading as malicious activity or reveal unauthorized tool usage that could be leveraged for lateral movement before a full-scale incident occurs.
rule HKTL_NET_GUID_NoAmci {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/med0x2e/NoAmci"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "352e80ec-72a5-4aa6-aabe-4f9a20393e8e" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects C# Red/Black-Team Tools via TypelibGUID”, including suggested filters and exclusions:
Scenario: Automated Patch Deployment with SCCM/Microsoft Endpoint Configuration Manager
ccmexec.exe) frequently loads C# assemblies to manage software updates. During the installation of .NET Framework patches or custom application deployments, it may instantiate specific Type Library GUIDs associated with Microsoft’s internal deployment tools, which share signatures with known red-team reconnaissance utilities.ParentImage is C:\Windows\CCM\CcmExec.exe AND the CommandLine contains keywords like “SoftwareUpdates” or “DeploymentType”.Scenario: Scheduled Backup Verification via Veeam or Commvault
typelibguid events that mimic the behavior of black-team lateral movement tools scanning for active services.DOMAIN\svc-veeam-backup) where the process name matches known backup agents like Veeam.Backup.Agent.exe or CommServe.exe.Scenario: Internal Compliance Scanning via Qualys or Tenable