Memory Allocation API Invoked by High-Risk Process
Detects calls to NtAllocateVirtualMemory originating from scripting engines or binaries executing from temporary user-controlled locations. This behavior is commonly associated with reflective loading, shellcode execution, and in-memory malware.
Microsoft Sentinel (KQL)

