MovieReaper VEH Hijack + RWX Memory for Hidden Syscall Execution
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Microsoft Sentinel (KQL)

