This rule identifies the execution of specialized C# Red and Black team tools by monitoring unique typelibguid values often associated with advanced security testing frameworks. Proactively hunting for these artifacts in Azure Sentinel is essential to distinguish legitimate internal security exercises from potential adversary activity that mimics trusted tooling to evade standard detection baselines.
rule HKTL_NET_GUID_GadgetToJScript {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/med0x2e/GadgetToJScript"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "af9c62a1-f8d2-4be0-b019-0a7873e81ea9" ascii nocase wide
$typelibguid1 = "b2b3adb0-1669-4b94-86cb-6dd682ddbea3" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the rule “Detects c# red/blue-team tools via typelibguid” in an enterprise environment, along with suggested filters or exclusions:
Scheduled Software Deployment (SCCM/MECM)
ccmexec.exe) runs a scheduled task to deploy Microsoft Office updates. During the installation phase, it invokes C#-based deployment agents that register COM type libraries, triggering the typelibguid detection on endpoints across the domain.ccmexec.exe or WuaAgent.exe, and the command line contains keywords like “Microsoft Office,” “Deployment,” or specific SCCM package IDs (e.g., *PackageID=*).Automated Patch Management via WSUS
wuauclt.exe or usocoreworker.exe) executes C# scripts to query the local update database, generating specific TypeLib GUIDs associated with the Microsoft Management Console (MMC) snap-ins used by the patching tool.Windows Update service context where the executable path is under C:\Windows\SoftwareDistribution\ or C:\Windows\System32\, specifically targeting known GUIDs associated with Microsoft.Update.Client.Enterprise Antivirus Real-Time Scanning