This hunt targets adversaries leveraging C#-based red and black team tools that expose unique TypeLibGUID artifacts to evade standard signature-based detection. Proactively hunting for these GUIDs in Azure Sentinel is critical because they often indicate early-stage reconnaissance or post-exploitation tool deployment that may precede more severe malicious activities.
rule HKTL_NET_GUID_UglyEXe {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/fashionproof/UglyEXe"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "233de44b-4ec1-475d-a7d6-16da48d6fc8d" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects c# red/blue-team tools via typelibguid,” along with suggested filters and exclusions:
Automated Patch Management Scans
TypelibGUID values during inventory sweeps. These scans often trigger on thousands of endpoints simultaneously, mimicking the behavior of reconnaissance tools used by Red Teams.NT SERVICE\ccmexec, IvantiAgent) and restrict detection to non-business hours if the scan is scheduled for maintenance windows.Software Asset Management & License Audits
TypelibGUID entries to map software versions to license compliance reports, generating high-volume alerts that resemble Black Team asset discovery activities.C:\Program Files\Flexera\...) and filter out events where the parent process is identified as a scheduled task (Task Scheduler service) running under the SYSTEM account.Enterprise Endpoint Detection & Response (EDR) Self-Scanning