CRPx0 PowerShell AMSI/ETW Unhooking via Builder Evasion Toggle
Detects the execution of PowerShell commands containing indicators of AMSI or ETW unhooking (e.g., references to amsi.dll, AmsiScanBuffer, EtwEventWrite, or VirtualProtect). This activity is commonly associated with attackers attempting to bypass endpoint security telemetry and antimalware scanning mechanisms prior to executing malicious payloads.
YARA-L

