This hunt hypothesis targets adversaries leveraging C#-based red and black team tools that expose unique TypeLibGUID artifacts to evade standard process-based detection. Proactively hunting for these specific identifiers in Azure Sentinel is critical because it enables the SOC team to distinguish legitimate administrative activities from stealthy tool usage often employed during initial reconnaissance or lateral movement phases.
rule HKTL_NET_GUID_AMSI_Handler {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/two06/AMSI_Handler"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "d829426c-986c-40a4-8ee2-58d14e090ef2" ascii nocase wide
$typelibguid1 = "86652418-5605-43fd-98b5-859828b072be" ascii nocase wide
$typelibguid2 = "1043649f-18e1-41c4-ae8d-ac4d9a86c2fc" ascii nocase wide
$typelibguid3 = "1d920b03-c537-4659-9a8c-09fb1d615e98" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Detects C# Red/Black-team tools via TypelibGUID rule, including suggested filters and exclusions:
Scenario: Automated Software Deployment via SCCM or Intune
typelibguid entries matching known attack surface patterns used by red/blue team tooling.ccmexec.exe, Microsoft.Windows.CloudExperienceHost.exe, or IntuneManagementExtension.exe, and the file path resides within the standard system deployment directories (e.g., C:\Program Files\Microsoft Intune Management Extension\).Scenario: Scheduled Antivirus Real-Time Scanning
typelibguid detection logic, mimicking the behavior of active reconnaissance tools.C:\Program Files\CrowdStrike\fs.exe, C:\Program Files\SentinelOne\Sentinel Agent\agent.exe) executing from their default installation directories, specifically filtering out events where the command line contains keywords like “scan,” “update,” or “signature.”Scenario: Internal IT Service Management (ITSM) Ticketing Agents