Operation DragonReturn AMSI Bypass via VirtualProtect Patching of AmsiOpenSession
Detects the execution of specific suspicious processes (Mixed Reality.exe, COU_ITR-1_to_4_AY2026-27.exe) or svchost.exe processes spawned from Windows Media Player paths, followed by suspicious loading of amsi.dll. This behavior is associated with the DragonReturn DLL sideloading and evasion chain.
Cortex XDR

