This detection identifies adversary activity involving custom or known Red/Black team C# tools by monitoring for specific TypeLibGUID artifacts within Azure Sentinel logs. Proactively hunting for these indicators allows the SOC to distinguish between legitimate security operations and potential malicious tool usage that may mimic standard administrative behavior, thereby reducing false positives in threat identification.
rule HKTL_NET_GUID_BypassUAC {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/cnsimo/BypassUAC"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "4e7c140d-bcc4-4b15-8c11-adb4e54cc39a" ascii nocase wide
$typelibguid1 = "cec553a7-1370-4bbc-9aae-b2f5dbde32b0" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Detects c# red/blue-team tools via typelibguid rule, including suggested filters and exclusions:
Scenario: Automated .NET Framework Updates via Windows Update Agent
Microsoft.WindowsUpdate.Orchestrator.Server) frequently executes C# binaries to install cumulative updates or patch the .NET runtime. These processes often instantiate standard COM libraries with typelibguid values that overlap with known red/blue team tool signatures (e.g., common logging or telemetry DLLs).usocoreworker.exe or DoSvc.exe and the command line contains arguments related to Microsoft-Windows-Update-Agent.Scenario: Scheduled Backup Jobs Using Veeam Agent for Microsoft Windows
VeeamAgentService.exe) that load specific Type Libraries for inventory scanning and snapshot creation. The typelibguid associated with these internal libraries may match the detection logic designed to identify active adversary tools, particularly during nightly maintenance windows.C:\Program Files\Veeam\Endpoint Backup\* and specific typelibguid values known to belong to Veeam’s internal telemetry components (e.g., Veeam.Backup.Agent.Telemetry).Scenario: Endpoint Detection and Response (EDR) Self-Scanning
typelibguid entries that mimic the behavior of external red-team reconnaissance tools (like