This hypothesis posits that adversaries executing C#-based red or black team tools within Azure Sentinel can be identified by analyzing unique typelib GUIDs generated during process creation. Proactively hunting for these specific identifiers allows the SOC team to distinguish legitimate security tooling from potential malicious activity, ensuring early visibility into reconnaissance and post-exploitation phases even when standard behavioral indicators are low severity.
rule HKTL_NET_GUID_UnstoppableService {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/malcomvetter/UnstoppableService"
author = "Arnim Rupp"
date = "2020-12-28"
strings:
$typelibguid0 = "0c117ee5-2a21-dead-beef-8cc7f0caaa86" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects c# red/black-team tools via typelibguid,” including suggested filters and exclusions:
Scenario: Automated CI/CD Pipeline Execution
msbuild.exe or dotnet.exe. These processes instantiate C# assemblies that generate specific TypeLib GUIDs identical to those used by security testing frameworks.C:\Program Files\Microsoft Visual Studio\*\MSBuild\Bin\msbuild.exe or C:\Windows\System32\dotnet.exe) running under specific service accounts like SYSTEM, NETWORK SERVICE, or dedicated CI/CD identities (e.g., svc-build-agent).Scenario: Scheduled Office 365 ProPlus Updates
OfficeClickToRun.exe) and associated background tasks often load C# components to manage add-ins and licensing. These components register TypeLib GUIDs that overlap with Red Team tool signatures (e.g., Mimikatz or SharpUp).OfficeClickToRun.exe and its child processes when they are executing scheduled tasks between 02:00 and 04:00 UTC, specifically filtering out events where the parent process is TaskHostW.exe.Scenario: Enterprise Endpoint Management (Intune/SCCM) Compliance Checks