This hunt targets adversaries leveraging C#-based Red and Black team tools that expose unique typelibguid artifacts during execution within Azure Sentinel. Proactively hunting for these specific identifiers allows the SOC to distinguish between legitimate security operations and potential adversary reconnaissance or tool deployment activities that may otherwise be obscured by low-severity noise.
rule HKTL_NET_GUID_aresskit {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/BlackVikingPro/aresskit"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "8dca0e42-f767-411d-9704-ae0ba4a44ae8" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects c# red/blue-team tools via typelibguid”, including suggested filters and exclusions:
Scenario: Automated Compliance Scanning via Microsoft Baseline Security Analyzer (MBSA)
typelibguid values during execution, mimicking the behavior of Red/Blue team assessment tools (like BloodHound or SharpUp).SYSTEM or a dedicated ComplianceServiceAccount context where the parent process is TaskScheduler.exe. Additionally, filter out specific known typelibguid values associated with standard Microsoft assessment frameworks (e.g., GUID-8F36E4C2...) if they are not part of your active Red/Blue tool inventory.Scenario: Endpoint DLP Agent Telemetry and Policy Updates
typelibguid events identical to those used by active reconnaissance tools like PowerSploit or Nmap-C#.C:\Program Files\Symantec\DLP\Agent\*) from triggering this rule. Implement a logic filter that suppresses alerts if the detected typelibguid matches the hash or signature of the organization’s approved D