CRPx0 ntdll.dll Unhooking to Evade EDR Userland Monitoring

Detects the CRPx0 ransomware technique of unhooking ntdll.dll in memory. This is achieved by reading the ntdll.dll file from disk and overwriting the in-memory .text section with a clean, unhooked version to bypass EDR monitoring and execute direct syscalls.