Sality binary persistence surviving reboot for P2P operation
This rule detects potentially malicious executables associated with Sality malware that consistently launch shortly after system startup across multiple boot sessions. It correlates boot events with process execution events within a 10-minute window post-startup to identify programs exhibiting persistence behavior across at least two separate boot instances.
Microsoft Sentinel (KQL)

