This hunt targets adversaries leveraging C#-based red and black team tools that generate unique typelibguid artifacts to establish persistence or execute reconnaissance within the environment. Proactively hunting for these specific GUIDs in Azure Sentinel is critical because their presence often indicates active threat emulation or sophisticated tool deployment that may otherwise blend into standard operational noise due to low severity alerts.
rule HKTL_NET_GUID_RunShellcode {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/zerosum0x0/RunShellcode"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "a3ec18a3-674c-4131-a7f5-acbed034b819" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Detects C# Red/Black-Team Tools via TypelibGUID” rule, tailored for an enterprise environment:
Scenario: Automated Software Deployment via SCCM or Intune
TypelibGUIDs during the installation of enterprise applications, mimicking the behavior of red-team reconnaissance tools like Cobalt Strike or Empire.C:\Windows\CCM\*, C:\Program Files\Microsoft Intune Management Extension\*) and restrict the rule to only trigger on user-initiated sessions rather than system background services (System or Network Service accounts).Scenario: Scheduled PowerShell Health Checks
.ps1) wrapped in C# wrappers to perform health checks, log rotation, or database connectivity tests. These scripts may load specific .NET assemblies that register TypelibGUIDs identical to those used by black-team post-exploitation frameworks.LOCAL SYSTEM account with command lines containing keywords like “HealthCheck,” “LogRotate,” or specific internal script paths (e.g., C:\Scripts\Ops\*). Additionally, filter by time-of-day to suppress alerts during known maintenance windows.Scenario: Enterprise Antivirus and EDR Scanning Engines