This hunt targets adversaries leveraging C#-based red and black team tools that share specific typelibguid identifiers with the NET_GUID malware family to establish persistence or conduct reconnaissance within Azure environments. Proactively hunting for these artifacts in Azure Sentinel is critical because their low-severity classification often allows them to evade standard alerting thresholds, enabling attackers to operate undetected during initial engagement phases.
rule HKTL_NET_GUID_SharpTask {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/jnqpblc/SharpTask"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "13e90a4d-bf7a-4d5a-9979-8b113e3166be" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the HKTL_NET_GUID_SharpTask detection rule in an enterprise environment, including suggested filters or exclusions:
Microsoft Visual Studio Installer & Build Agents
msbuild.exe process often registers COM type libraries (typelibguid) that match the signature of Red/Black team tools used for vulnerability scanning and code analysis within the development lifecycle.NT SERVICE\BuildAgent, AzureDevOpsService) running under paths containing \Program Files\Microsoft Visual Studio\ or \Jenkins\workspace\.Enterprise Endpoint Management Updates
typelibguid check even though they are standard administrative tools rather than active threat hunting utilities.ccmexec.exe, IntuneManagementExtension.exe, or JamfProAgent.exe when the action occurs during defined maintenance windows (e.g., 02:00–04:00 local time).Third-Party Security Scanner Scans