WordlistLoader/Amatera Evasion Chain: Module Unhooking + ETW Bypass + PoolParty Injection
This rule detects a multi-stage attack chain characteristic of the WordlistLoader/Amatera malware. It identifies the sequential occurrence of module unhooking (via CreateToolhelp32Snapshot), ETW bypass (via AddVectoredExceptionHandler), and remote process injection (via WriteProcessMemory, CreateRemoteThread, etc.) originating from the same process within a 15-minute window.
Microsoft Sentinel (KQL)

