This hypothesis posits that adversaries are leveraging custom C# Red and Black team tools within the Azure environment to establish persistence or conduct reconnaissance through unique TypeLibGUID identifiers. The SOC team should proactively hunt for these specific GUIDs in Azure Sentinel to distinguish legitimate security tooling from potential malicious activity, ensuring early visibility into specialized threat actor behaviors that may bypass standard signature-based detections.
rule HKTL_NET_GUID_TellMeYourSecrets {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/0xbadjuju/TellMeYourSecrets"
author = "Arnim Rupp"
date = "2020-12-28"
strings:
$typelibguid0 = "9b448062-7219-4d82-9a0a-e784c4b3aa27" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the “Detects C# Red/Black-Team Tools via TypelibGUID” rule, along with suggested filters:
Scenario: Automated Deployment Pipeline Execution
Microsoft.TeamFoundation.Build.Client or similar C# libraries to orchestrate deployments. These tools often instantiate COM objects that match the specific TypelibGUIDs associated with Red Team automation suites.\BuildAgent\ or \AzureDevOps\ and the parent process is TfsBuild.exe or dotnet.exe.Scenario: Scheduled Endpoint Management Tasks
SYSTEM account with executable names like ccmexec.exe, IntuneManagementExtension.exe, or IvantiAgent.exe.Scenario: Internal Reporting and Analytics Dashboards
w3wp.exe (IIS Application Pool) and the user context belongs to a service account named BI-Service or ReportServer.