Sality-infected host propagation: scan burst then new-binary execution
Detects a host performing high-volume outbound network scanning (connecting to 10 or more distinct public IP addresses within 15 minutes) followed by the execution of an executable file created in common suspicious directories (AppData, Temp, Downloads, or Users/Public) within a short window (10 minutes after the scan). This pattern is indicative of a compromised host scanning for lateral movement opportunities or propagation targets, followed by the deployment of malicious tooling.
Microsoft Sentinel (KQL)

