This detection rule identifies specific SafeNet code execution patterns that may indicate legitimate cryptographic operations or subtle anomalies within the software supply chain. Proactively hunting for these features in Azure Sentinel allows the SOC team to establish a behavioral baseline and distinguish between normal SafeNet activity and potential early-stage compromise attempts before they escalate into critical incidents.
rule SafeNetCode : SafeNet Family
{
meta:
description = "SafeNet code features"
author = "Seth Hardy"
last_modified = "2014-07-16"
strings:
// add edi, 14h; cmp edi, 50D0F8h
$ = { 83 C7 14 81 FF F8 D0 40 00 }
condition:
any of them
}
This YARA rule can be deployed in the following contexts:
Here are 4 specific false positive scenarios for the SafeNet Code Features detection rule in an enterprise environment, along with targeted filtering strategies:
Automated License Renewal via SafeKey Management Server
SafeNet Sentinel service reading and writing to the code feature registry, generating high-volume events that mimic suspicious code execution patterns due to the cryptographic operations involved.skms-prod-01.corp.local) where the process name is SentinelLicensing.exe and the user context is the local system account (NT AUTHORITY\SYSTEM).Endpoint Deployment of SafeNet Authentication Client
ccmexec.exe) invokes the SafeNet installer, which registers new code features and updates the local registry, triggering the rule on every affected machine.ccmexec.exe or msiexec.exe, and the command line arguments contain keywords such as /qn, SafeNet, or AuthenticationClient.Database Backup Integration with SafeNet Key Secure
vbrservice.exe process to interact heavily with SafeNet code features (specifically