This hunt hypothesis targets adversary behavior where attackers execute C#-based red or black team tools that register unique TypeLibGUID identifiers to establish persistence or perform reconnaissance within the environment. The SOC team should proactively hunt for these specific GUIDs in Azure Sentinel because they serve as distinct fingerprints that can reveal stealthy tool usage often missed by standard signature-based detections, enabling early identification of both authorized testing and potential malicious activity.
rule HKTL_NET_GUID_Mass_RAT {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/NYAN-x-CAT/Mass-RAT"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "6c43a753-9565-48b2-a372-4210bb1e0d75" ascii nocase wide
$typelibguid1 = "92ba2a7e-c198-4d43-929e-1cfe54b64d95" ascii nocase wide
$typelibguid2 = "4cb9bbee-fb92-44fa-a427-b7245befc2f3" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Detects C# Red/Black-Team Tools via TypelibGUID” rule, including suggested filters and exclusions:
Scenario: Automated Patch Deployment via SCCM or Intune
TypelibGUID signatures with known red-team tools like Cobalt Strike or Beacon.ccmexec.exe (SCCM) or IntuneManagementExtension.exe, and the command line contains standard patching arguments (e.g., /deploy, /install).Scenario: Scheduled Backup Verification Jobs
TypelibGUID entries indistinguishable from black-team reconnaissance tools like PowerShell Empire or Covenant.VeeamAgent.exe, cvdagent.exe) running during defined maintenance windows, specifically filtering out events where the process path matches the enterprise backup installation directory.Scenario: Endpoint Detection and Response (EDR) Self-Scanning
TypelibGUID patterns associated with red-team post-exploitation tools like