This detection identifies potential adversary activity by monitoring for specific TypeLibGUIDs associated with common C# offensive and defensive tools used in Azure Sentinel environments. Proactive hunting is essential to uncover stealthy tool deployments that may evade standard signature-based alerts, allowing analysts to validate legitimate usage or isolate early-stage reconnaissance efforts before they escalate into broader incidents.
rule HKTL_NET_GUID_sitrep {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/mdsecactivebreach/sitrep"
author = "Arnim Rupp"
date = "2020-12-28"
strings:
$typelibguid0 = "12963497-988f-46c0-9212-28b4b2b1831b" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the “Detects c# red/black-team tools via typelibguid” rule, including suggested filters and exclusions:
Scenario: Microsoft Office Deployment Tool (ODT) Updates
OfficeDeploymentTool.exe frequently executes during scheduled maintenance windows to update or repair Office 365 suites. As a C# application, it registers specific TypeLib GUIDs that overlap with known Red/Black team reconnaissance tools.C:\Program Files\Microsoft Office Deployment Tool\OfficeDeploymentTool.exe and filter out events occurring during defined maintenance windows (e.g., 02:00–04:00 UTC).Scenario: System Center Configuration Manager (SCCM) Client Tasks
ccmsetup.exe or ccmexec.exe) runs periodic inventory and policy compliance checks. These C#-based components often instantiate TypeLib GUIDs associated with network scanning utilities, mimicking the behavior of Black Team asset discovery tools.Microsoft.ConfigurationManagement or paths starting with C:\Program Files (x86)\Microsoft Configuration Manager\.Scenario: Automated PowerShell Script Execution via Task Scheduler
ParentProcessName is TaskSchedulerService.exe and the command line contains keywords like “Backup,” “LogRotation,” or specific internal script names