Sality self-propagation via autorun.inf and network share infection
This rule monitors for two indicators of potentially self-propagating malware: the creation of autorun.inf files on removable or network-mapped drives combined with active SMB network connections (suggesting worm propagation), and the rapid creation of multiple unique executable files across multiple devices (suggesting an outbreak or worm activity).
Microsoft Sentinel (KQL)

