This hunt hypothesis identifies active C# Red and Black team security tools by analyzing unique TypeLibGUID signatures within Azure Sentinel logs to distinguish legitimate testing activities from potential adversary tooling. Proactively hunting for these indicators allows the SOC team to validate authorized security operations while rapidly detecting unauthorized or anomalous use of similar C# frameworks that could signal stealthy reconnaissance or lateral movement attempts.
rule HKTL_NET_GUID_SharpWMI {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/GhostPack/SharpWMI"
author = "Arnim Rupp"
date = "2020-12-28"
strings:
$typelibguid0 = "6dd22880-dac5-4b4d-9c91-8c35cc7b8180" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios and corresponding exclusion strategies for the Detects c# red/black-team tools via typelibguid rule:
Scenario: Automated Software Deployment via Microsoft Endpoint Configuration Manager (SCCM) or Intune.
ParentProcessName is ccmexec.exe (SCCM) or IntuneManagementExtension.exe, and the CommandLine contains keywords like “Install”, “Update”, or “Deployment”.Scenario: Execution of Microsoft Visual Studio Build Agents on CI/CD Servers.
ci-server-01, jenkins-node) or where the ProcessName is msbuild.exe and the execution occurs within a dedicated “Build” user context (e.g., NT SERVICE\TeamFoundationBuildAgent).Scenario: Scheduled PowerShell Automation Scripts utilizing .NET Assemblies.
ProcessName is pwsh.exe (or powershell.exe) and