CRPx0 In-Memory AMSI/ETW Patching to Blind Security Tooling
This rule detects attempts to patch critical Windows functions used for security instrumentation, specifically 'AmsiScanBuffer' within 'amsi.dll' (often for bypassing AMSI) or 'EtwEventWrite' within 'ntdll.dll' (often for disabling ETW logging). This activity is highly indicative of defensive evasion techniques used by malware or malicious actors to hide their behavior from security tools.
CQL

