Operation DragonReturn: AMSI AmsiOpenSession Patch by Suspicious Process
Detects suspicious activities often associated with malware (such as DcRAT or Operation DragonReturn) including the loading of amsi.dll by unauthorized processes in writable directories to facilitate patching of AMSI, and unauthorized cross-process memory writing into svchost.exe from non-system, potentially unsigned or suspicious processes.
SentinelOne

