MuddyWater FakeUpdate Self-Injection via VirtualAlloc+WriteProcessMemory

This rule detects instances where a process attempts to open a handle to itself with high-privilege access rights (e.g., PROCESS_ALL_ACCESS, PROCESS_VM_WRITE, PROCESS_VM_OPERATION). This behavior is often indicative of self-injection, a technique used by malicious code to modify its own memory space or inject shellcode, evading detection and bypassing certain security controls.