ShieldCrash: ntdll.dll copied into GUID staging ADS path

This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.