This hunt targets adversaries deploying C# red and black team tools that leverage typelibguid to evade antivirus detection within the NET_GUID malware family. Proactively hunting for this behavior in Azure Sentinel is critical because these legitimate-looking artifacts are frequently repurposed by threat actors to establish persistence while remaining invisible to standard signature-based defenses.
rule HKTL_NET_GUID_AV_Evasion_Tool {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/1y0n/AV_Evasion_Tool"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "1937ee16-57d7-4a5f-88f4-024244f19dc6" ascii nocase wide
$typelibguid1 = "7898617d-08d2-4297-adfe-5edd5c1b828b" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Detects c# red/black-team tools via typelibguid rule, tailored for an enterprise environment:
Scenario: Automated Patch Deployment via SCCM/MECM
ccmexec.exe) frequently executes C#-based deployment agents to install or update software packages. These agents often instantiate COM objects using specific typelibguid values to interact with the Windows Installer service, mimicking the behavior of security tools scanning for AV evasion.ccmexec.exe AND the command line contains arguments related to software updates (e.g., /install, /update) or specific SCCM package IDs.Scenario: Microsoft Defender Antivirus Real-Time Scanning
MsMpEng.exe) utilizes C# components for its heuristic analysis and cloud protection modules. During routine real-time scanning, it loads various type libraries to enumerate file metadata, which can generate typelibguid events identical to those flagged by the NET_GUID malware family logic.C:\Program Files\Windows Defender\MsMpEng.exe when the detected typelibguid matches known Microsoft-signed GUIDs (e.g., starting with {000...} or verified against a whitelist of MSFT signatures).Scenario: Scheduled PowerShell Health Checks
powershell.exe) to perform system health checks, log rotation, or compliance reporting. These scripts frequently load C# assemblies (e.g., System.Management.Automation.dll) which register type libraries dynamically during execution, triggering the detection logic intended for red-team