This hunt identifies the execution of C#-based red and black team tools by analyzing unique TypeLibGUID values often embedded in legitimate security utilities. Proactively hunting for these artifacts in Azure Sentinel is essential to distinguish authorized testing activities from potential adversary use of similar tooling, ensuring that low-severity signals are not overlooked during initial threat assessments.
rule HKTL_NET_GUID_StormKitty {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/LimerBoy/StormKitty"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "a16abbb4-985b-4db2-a80c-21268b26c73d" ascii nocase wide
$typelibguid1 = "98075331-1f86-48c8-ae29-29da39a8f98b" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects C# Red/Black-Team Tools via TypelibGUID” in an enterprise environment, along with suggested filters:
Scenario: Automated Backup and Maintenance Scripts
typelibguid values associated with standard .NET assemblies used for system health checks, which overlap with the GUIDs monitored by red team frameworks.DOMAIN\svc_backup) or restrict detection to specific parent process names like Veeam.Backup.Service.exe and PowerShell.exe when launched from a scheduled task path (C:\Windows\System32\Tasks\).Scenario: Software Deployment via SCCM/MECM
typelibguid signatures that mimic those used by reconnaissance or lateral movement tools in red team engagements, particularly during software inventory scans.ccmexec.exe (the core SCCM agent) and its child processes (CcmExec\Microsoft.ConfigurationManager.SCCMClient.exe). Additionally, filter by the specific user context of the deployment service account (e.g., DOMAIN\SysAdmin_Deploy).Scenario: Endpoint Detection and Response (EDR) Self-Scanning