Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
3
2
1
1
Platforms
3
Products / Services
10,351
9,601
6,991
4,335
3,859
Detects a process reporting the display name TVHelper whose backing executable is actually libdevice.so or another binary outside standard OEM app directories, consistent with Kimwolf v7 relabeling its payload as the legitimate Android TV helper service to evade casual process-list review.
Detects a process reporting the name netd_service whose backing executable path does not match genuine Android system netd binary locations, indicating Kimwolf v7 process masquerading to blend into legitimate network daemon activity.
Detects su-privileged execution of an embedded ELF payload (libdevice.so or the disguised com.n2.systemservice package) from an application-data directory, consistent with the Kimwolf v7 Android dropper establishing persistence outside standard system binary paths.
