This hunt hypothesis targets adversaries leveraging C#-based red and black team tools that expose unique TypeLibGUID artifacts to evade standard signature-based detection. Proactively hunting for these specific GUIDs in Azure Sentinel is critical because it enables the SOC team to identify sophisticated reconnaissance or post-exploitation activities that often bypass traditional endpoint protection mechanisms.
rule HKTL_NET_GUID_clr_meterpreter {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/OJ/clr-meterpreter"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "6840b249-1a0e-433b-be79-a927696ea4b3" ascii nocase wide
$typelibguid1 = "67c09d37-ac18-4f15-8dd6-b5da721c0df6" ascii nocase wide
$typelibguid2 = "e05d0deb-d724-4448-8c4c-53d6a8e670f3" ascii nocase wide
$typelibguid3 = "c3cc72bf-62a2-4034-af66-e66da73e425d" ascii nocase wide
$typelibguid4 = "7ace3762-d8e1-4969-a5a0-dcaf7b18164e" ascii nocase wide
$typelibguid5 = "3296e4a3-94b5-4232-b423-44f4c7421cb3" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 6 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Detects C# Red/Black-Team Tools via TypelibGUID” rule in an enterprise environment, along with suggested filters or exclusions:
Scenario: Automated Patch Management Deployment
typelibguid values that match the rule’s signature for red-team reconnaissance tools during the installation phase of Windows Updates or application patches.NT SERVICE\ccmexec, IvantiAgent) and restrict the alert to exclude execution paths located within standard software distribution directories (e.g., C:\Program Files\Microsoft Configuration Manager\).Scenario: Scheduled SQL Database Maintenance Jobs
typelibguid identifiers with security assessment frameworks used by red teams.sqlagent.exe and the execution path containing \Microsoft SQL Server\MSSQL*\MSSQL\Binn\. Additionally, filter for specific scheduled task names known to trigger these maintenance routines (e.g., “SQLServerMaintenanceTask”).Scenario: Endpoint Security Agent Self-Updates