This hunt targets adversaries leveraging C#-based offensive or defensive tools that expose unique typelibguid identifiers to evade standard signature-based detection. Proactively hunting for these artifacts in Azure Sentinel is critical because identifying known tool signatures early allows the SOC team to distinguish legitimate administrative activity from potential red-team exercises or stealthy initial access attempts before they escalate into higher-severity incidents.
rule HKTL_NET_GUID_SharpMiniDump {
meta:
description = "Detects c# red/black-team tools via typelibguid"
reference = "https://github.com/b4rtik/SharpMiniDump"
author = "Arnim Rupp"
date = "2020-12-13"
strings:
$typelibguid0 = "6ffccf81-6c3c-4d3f-b15f-35a86d0b497f" ascii nocase wide
condition:
(uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550) and any of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Detects C# Red/Black-Team Tools via TypelibGUID rule, including suggested filters and exclusions:
Microsoft Office Add-in Initialization
TypelibGUIDs. These GUIDs often match known red-team tool signatures because many enterprise tools share common .NET base libraries used by security researchers.OUTLOOK.EXE or EXCEL.EXE and the loaded DLL path contains \Microsoft Office\Office16\ or \Program Files\Common Files\.Automated Patch Management Scans
TypelibGUID events that mimic the behavior of reconnaissance tools like BloodHound or SharpUp.IvantiAgent.exe, SMSHOST.EXE) running under the local system account (NT AUTHORITY\SYSTEM) during scheduled maintenance windows.CI/CD Pipeline Build Agents