Sality rootkit hiding via kernel hook + security tool tampering
Detects malicious activity patterns characteristic of Sality or similar rootkits, which involve disabling endpoint protection mechanisms (AV/Firewall) in conjunction with kernel-mode driver installation or hooking operations to persist and hide malware activity.
Microsoft Sentinel (KQL)

