GhostContainer AMSI Bypass via amsi.dll Patch in w3wp.exe

This rule detects attempts by an IIS worker process (w3wp.exe) to tamper with or disable the Antimalware Scan Interface (AMSI) by monitoring for specific non-standard provider registrations or scan buffer patching events. This activity often indicates an attacker attempting to bypass security scanning within a web-based application process.