This rule identifies the execution of known .NET-based Red and Black team security tools by analyzing process names to distinguish legitimate testing activities from potential adversary use of similar frameworks for stealthy operations. Proactively hunting for these signals in Azure Sentinel allows the SOC team to validate authorized tool usage, reduce false positives during security exercises, and detect unauthorized deployments that may indicate an attacker leveraging .NET environments to establish a foothold or evade detection.
rule HKTL_NET_NAME_SharpHose {
meta:
description = "Detects .NET red/black-team tools via name"
reference = "https://github.com/ustayready/SharpHose"
author = "Arnim Rupp"
date = "2021-01-22"
strings:
$name = "SharpHose" ascii wide
$compile = "AssemblyTitle" ascii wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the rule “Detects .NET red/blue-team tools via name,” along with suggested filters or exclusions:
Scenario: Automated Backup Jobs using PowerShell Modules
Veeam.Backup.Service.exe or similar to manage data snapshots. These processes frequently match the naming patterns of Red/Blue team tools like Veeam.NET or generic .NET tool names.DOMAIN\BackupSvc) and restrict detection to paths outside standard backup directories (e.g., exclude C:\Program Files\Veeam Backup & Replication\).Scenario: Endpoint Protection Scanning Engines
FalconSensor.exe or SentinelOneAgent.dll. These often invoke internal .NET tools for real-time heuristic analysis, which can mimic the naming convention of security testing frameworks like Cobalt Strike Beacon or Mimikatz.falcon.sys or s1agent.exe).Scenario: Scheduled CI/CD Pipeline Agents
AzureDevOps.Agent.exe or Jenkins.BuildTool.dll) to compile and