This hunt hypothesis targets adversaries leveraging C#-based red and black team tools that expose unique TypeLibGUID identifiers to evade standard signature-based detection. Proactively hunting for these specific GUIDs in Azure Sentinel is critical because they often indicate advanced reconnaissance or post-exploitation activities that may bypass initial low-severity alerts, allowing the SOC team to identify persistent tooling before it escalates into a broader incident.
rule HKTL_NET_GUID_EducationalRAT {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/securesean/EducationalRAT"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "8a18fbcf-8cac-482d-8ab7-08a44f0e278e" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypelibGuid rule, including suggested filters and exclusions:
Scenario: Automated Software Deployment via SCCM or Intune
TypelibGuid signatures with common red-team tools like Cobalt Strike’s Beacon or Mimikatz.\Microsoft Antimalware\ or \Program Files (x86)\Microsoft Intune Agent\. Additionally, filter for parent processes named ccmexec.exe, OneDrive.exe, or MsMpEng.exe.Scenario: Scheduled PowerShell Maintenance Jobs
powershell.exe) to perform log rotation, disk cleanup, or user account auditing. When these scripts invoke .NET assemblies (e.g., for Active Directory management or Azure AD synchronization), they generate TypelibGuid events that mimic the behavior of C# reconnaissance tools.powershell.exe when launched by the “System” user account and triggered via Task Scheduler (TaskScheduler). Specifically, filter out instances where the command line arguments contain standard maintenance keywords like -Command, -File, or specific module names like ActiveDirectory or AzureAD.Scenario: Enterprise Antivirus Real-Time Scanning