This hunt hypothesis targets adversaries leveraging custom or known .NET-based red and black team tools that can be uniquely identified by their specific TypeLibGUID signatures within process execution logs. Proactively hunting for these indicators in Azure Sentinel is essential to distinguish legitimate security tooling from malicious .NET payloads, thereby reducing false positives while uncovering stealthy reconnaissance activities that may evade standard signature-based detections.
rule HKTL_NET_GUID_NashaVM {
meta:
description = "Detects .NET red/black-team tools via typelibguid"
reference = "https://github.com/Mrakovic-ORG/NashaVM"
author = "Arnim Rupp"
date = "2021-01-21"
strings:
$typelibguid0 = "f9e63498-6e92-4afd-8c13-4f63a3d964c3" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the rule “Detects .NET red/black-team tools via typelibguid,” along with suggested filters or exclusions:
Scenario: Automated Backup and Reporting Services
ProcessName (e.g., Veeam.Backup.Service.exe, MsMgmtService.exe) and restrict detection to non-standard user accounts (exclude SYSTEM or specific service accounts like BackupSvc).Scenario: Endpoint Detection and Response (EDR) Scanning
CrowdStrikeService, WdNisSvc) and filter by CommandLine containing keywords like “scan”, “update”, or “healthcheck”.Scenario: Office 365 / Microsoft Teams Update Mechanisms