This hunt hypothesis targets adversaries leveraging custom or known .NET-based offensive and defensive utilities to establish persistence or conduct reconnaissance within Azure Sentinel environments. Proactively hunting for these specific tool names allows the SOC team to distinguish legitimate administrative activity from potential red-team exercises or stealthy attacker movements that might otherwise be obscured by standard low-severity alerts.
rule HKTL_NET_NAME_Infrastructure_Assessment {
meta:
description = "Detects .NET red/black-team tools via name"
reference = "https://github.com/NyaMeeEain/Infrastructure-Assessment"
author = "Arnim Rupp"
date = "2021-01-22"
strings:
$name = "Infrastructure-Assessment" ascii wide
$compile = "AssemblyTitle" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the rule “Detects .NET red/blue-team tools via name,” including suggested filters and exclusions:
Scenario: Automated Vulnerability Scanning by Admin
MSTest.exe or SecurityComplianceScanner.dll that match the rule’s naming pattern for red-team tools.MSTest.exe, NessusAgent.exe) combined with the Parent Process being TaskScheduler.exe or a specific admin service account (e.g., DOMAIN\svc-scanner).Scenario: CI/CD Pipeline Build Artifacts
dotnet.exe, MSBuild.exe, or custom tooling named RedTeamSimulator.dll which mimics the naming convention of red-team simulation tools.build-server-01) and the User Account belongs to the service group (e.g., DOMAIN\svc-cicd-build).Scenario: Enterprise Endpoint Management Updates
IntuneManagementExtension.exe or similar, which may contain substrings triggering the rule if the