This hunt targets adversaries leveraging C#-based red and black team tools that expose unique TypeLibGUID identifiers to establish a baseline of known security utilities within the environment. Proactively hunting for these signatures in Azure Sentinel is essential to distinguish legitimate defensive tooling from malicious C# payloads, thereby reducing false positives and accelerating incident response during active engagements.
rule HKTL_NET_GUID_ShellCodeRunner {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/antman1p/ShellCodeRunner"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "634874b7-bf85-400c-82f0-7f3b4659549a" ascii nocase wide
$typelibguid1 = "2f9c3053-077f-45f2-b207-87c3c7b8f054" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypelibGUID rule in an enterprise environment, along with suggested filters or exclusions:
Microsoft Office Click-to-Run Updates and Add-ins
typelibguid entries during background updates, installation of language packs, or the loading of third-party COM add-ins (e.g., Adobe Acrobat PDF Maker or ABBYY FineReader). These legitimate C# components often mimic the GUID patterns associated with red-team tools.C:\Program Files\Microsoft Office\root\Office16 and C:\Program Files (x86)\Common Files\microsoft shared\OFFICE16. Additionally, filter out specific known benign GUIDs associated with major vendors like Adobe ({000209FF-0000-0000-C000-000000000046}) and ABBYY.Enterprise Endpoint Protection Scanners (e.g., CrowdStrike, Carbon Black)
typelibguid values that can be flagged as “Red Team” reconnaissance tools.cs.exe, cb.exe, SentinelOneAgent.exe) and exclude any typelibguid events where the image path contains standard security vendor directories like C:\Program Files\CrowdStrike\ or `C:\