This hunt hypothesis targets adversaries leveraging C#-based red and black team tools that generate unique TypeLibGUID artifacts to establish persistence or conduct reconnaissance within the environment. Proactively hunting for these specific GUIDs in Azure Sentinel is essential because they often serve as early indicators of advanced tooling usage, allowing the SOC team to distinguish between legitimate administrative activities and potential adversary operations before they escalate into critical incidents.
rule HKTL_NET_GUID_ExternalC2 {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/ryhanson/ExternalC2"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "7266acbb-b10d-4873-9b99-12d2043b1d4e" ascii nocase wide
$typelibguid1 = "5d9515d0-df67-40ed-a6b2-6619620ef0ef" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypeLibGuid rule, tailored for an enterprise environment:
Microsoft Office Click-to-Run Updates
OfficeClickToRun.exe) frequently registers or updates COM type libraries during background patching cycles. These processes often utilize standard C# assemblies that generate typelibguid entries indistinguishable from legitimate Red/Blue team reconnaissance tools (e.g., Mimic, BloodHound).C:\Program Files\Microsoft Office\root\Office*\OfficeClickToRun.exe and filter out TypeLibGUIDs associated with known Microsoft Office namespaces (e.g., starting with {000245...}).Automated SCCM/Intune Agent Deployment
ccmexec.exe or Microsoft.IntuneManagementAgent) executes scheduled maintenance tasks that involve installing .NET components. These installations often trigger the registration of new TypeLibGUIDs for internal management libraries, mimicking the footprint of a deployed security assessment tool.NT SERVICE\ccmexec or Microsoft.IntuneManagementAgent service accounts and specifically exclude GUIDs registered within the last 24 hours if the parent process is identified as a known patching agent.Enterprise Endpoint Protection Scans (e.g., CrowdStrike, SentinelOne)