This hunt hypothesis targets adversaries leveraging custom or known .NET-based offensive and defensive tools that register unique TypeLib GUIDs to establish persistence or execute reconnaissance within the environment. A SOC team should proactively hunt for these indicators in Azure Sentinel because standard signature-based detections often miss novel tooling, making the identification of anomalous TypeLib registrations a critical early-warning signal for potential red-team exercises or stealthy attacker activity.
rule HKTL_NET_GUID_ADSearch {
meta:
description = "Detects .NET red/black-team tools via typelibguid"
reference = "https://github.com/tomcarver16/ADSearch"
author = "Arnim Rupp"
date = "2021-01-21"
strings:
$typelibguid0 = "4da5f1b7-8936-4413-91f7-57d6e072b4a7" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the rule “Detects .NET red/black-team tools via typelibguid”, including suggested filters and exclusions:
Scenario: Automated Backup Script Execution
SharpUp or BloodHound.Veeam.Backup.Service.exe, commvault.cmd) and the execution time aligns with defined maintenance windows (e.g., 02:00–04:00 local time).Scenario: Microsoft Endpoint Configuration Manager (SCCM) Updates
ccmexec.exe process launching temporary .NET assemblies for inventory collection.\Microsoft Endpoint\ or C:\Program Files (x86)\Microsoft Configuration Manager\, specifically targeting the TypeLib GUIDs associated with standard SCCM components rather than red-team specific ones.Scenario: Active Directory Health Monitoring Tools
SharpView or PowerSploit.