This hypothesis posits that adversaries are deploying C#-based Red and Black team tools within the environment to establish persistence or conduct reconnaissance, identifiable by unique TypeLibGUID artifacts in process execution logs. The SOC team should proactively hunt for these specific GUIDs in Azure Sentinel to distinguish legitimate security tooling from malicious activity masquerading as standard administrative utilities, thereby reducing false positives and enhancing visibility into internal threat operations.
rule HKTL_NET_GUID_CsharpAmsiBypass {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/WayneJLee/CsharpAmsiBypass"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "4ab3b95d-373c-4197-8ee3-fe0fa66ca122" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the rule “Detects C# Red/Black-Team Tools via TypelibGUID”, along with suggested filters or exclusions:
Scenario: Automated Patch Deployment via SCCM/Microsoft Endpoint Configuration Manager
ccmexec.exe process invokes C# compilation tools that register specific TypeLib GUIDs associated with the deployment agent’s internal libraries.C:\Windows\CCM\CcmExec.exe and the command line contains arguments related to “SoftwareUpdate” or “Deployment”.Scenario: Scheduled Backup Verification Jobs
VeeamBackupAgent.exe or a proprietary script) to verify backup integrity. This tool utilizes the .NET Framework’s reflection capabilities, triggering the registration of standard TypeLib GUIDs that overlap with those used by red-team reconnaissance tools like BloodHound or SharpUp.SYSTEM account during specific maintenance windows (e.g., 02:00–04:00) where the process name matches known backup agents (Veeam, Commvault, Altiris) and the TypeLib GUID corresponds to standard .NET runtime libraries rather than custom red-team signatures.Scenario: Development Environment Build Pipelines (CI/CD)