In-process AMSI/ETW patching with direct-syscall EDR-hook bypass

Detects coordinated EDR-blinding techniques where a process performs in-memory patching of AMSI (AmsiScanBuffer) or ETW (EtwEventWrite) while simultaneously executing direct syscalls to bypass standard ntdll.dll hooked exports. This combination is highly indicative of malicious activity attempting to evade endpoint security instrumentation.