AMSI/ETW Patching via In-Memory Hook Removal (amsi.dll/ntdll.dll)
Detects unauthorized in-memory memory modifications (specifically writing to memory segments with execute permissions) targeting critical security functions within 'amsi.dll' or 'ntdll.dll', such as 'AmsiScanBuffer' or 'EtwEventWrite'. This activity is characteristic of AMSI/ETW blinding, a technique used by threat actors to disable endpoint security scanning and event tracing capabilities.
Microsoft Sentinel (KQL)

