This hunt targets adversaries utilizing C#-based Red and Black team tools that register unique TypeLibGUIDs to establish persistence or execute reconnaissance within Windows environments. Proactively hunting for these specific GUID signatures in Azure Sentinel is critical because they often represent known tooling used by threat actors to blend with legitimate administrative activity, allowing the SOC to identify early-stage lateral movement or post-exploitation behaviors before they escalate into high-severity incidents.
rule HKTL_NET_GUID_CinaRAT {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/wearelegal/CinaRAT"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "8586f5b1-2ef4-4f35-bd45-c6206fdc0ebc" ascii nocase wide
$typelibguid1 = "fe184ab5-f153-4179-9bf5-50523987cf1f" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the “Detects c# red/blue-team tools via typelibguid” rule, including suggested filters and exclusions:
Automated Patch Management Deployment
System.Runtime.InteropServices) which contain known Red/Blue team tool GUIDs used for telemetry and reporting within the management suite itself.NT SERVICE\SCCM or Microsoft.Windows.CloudManagementService, specifically when the parent process is ccmexec.exe or IntuneAgent.exe.Enterprise Antivirus Real-Time Scanning
typelibguid signatures with external red-team reconnaissance tools like BloodHound or SharpHound.C:\Program Files\CrowdStrike\) and filter out events where the process name matches known AV service executables (e.g., csfalcon.exe, rtvscan.exe).Scheduled SQL Server Maintenance Jobs