This detection identifies adversary activity by monitoring for specific TypeLibGUID signatures associated with common C# red and blue team tools often used during reconnaissance or post-exploitation phases. Proactive hunting for these indicators in Azure Sentinel is essential to distinguish legitimate security operations from potential malicious tool usage that may evade standard signature-based defenses.
rule HKTL_NET_GUID_CVE_2019_1064 {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/RythmStick/CVE-2019-1064"
author = "Arnim Rupp"
date = "2020-12-28"
strings:
$typelibguid0 = "ff97e98a-635e-4ea9-b2d0-1a13f6bdbc38" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the “Detects C# Red/Black-Team Tools via TypelibGUID” rule, including suggested filters and exclusions:
Scenario: Microsoft Office Click-to-Run Updates
OfficeClickToRun.exe process frequently loads C# assemblies during background updates or feature installation. These assemblies often utilize standard .NET TypeLib GUIDs that overlap with Red/Blue team reconnaissance tools (e.g., specific GUIDs used by tools like BloodHound or SharpUp).OfficeClickToRun.exe process path (C:\Program Files\Microsoft Office root\Office16\...) from triggering this rule, or filter out events where the parent process is Update.exe (Microsoft Click-to-Run Service) with a specific command line argument containing /update.Scenario: Scheduled PowerShell Automation Scripts
powershell.exe process when the command line contains specific keywords like -ExecutionPolicy Bypass, and the parent process is Task Scheduler (svchost.exe -k netsvcs). Additionally, whitelist known internal script paths (e.g., C:\Scripts\IT_Ops\) in the detection logic.Scenario: Endpoint Detection and Response (EDR) Health Checks