Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects a process reporting the display name TVHelper whose backing executable is actually libdevice.so or another binary outside standard OEM app directories, consistent with Kimwolf v7 relabeling its payload as the legitimate Android TV helper service to evade casual process-list review.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a process reporting the name netd_service whose backing executable path does not match genuine Android system netd binary locations, indicating Kimwolf v7 process masquerading to blend into legitimate network daemon activity.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects su-privileged execution of an embedded ELF payload (libdevice.so or the disguised com.n2.systemservice package) from an application-data directory, consistent with the Kimwolf v7 Android dropper establishing persistence outside standard system binary paths.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001