MovieReaper VEH-based RWX shellcode syscall evasion

Detects sophisticated process injection behavior where malicious shellcode is mapped into RWX memory. The payload utilizes a Vectored Exception Handler (VEH) and deliberate 0xCC (breakpoint) instructions to intercept execution and redirect it into raw syscall stubs (e.g., NtProtectVirtualMemory). This technique is designed to bypass security product API hooking by avoiding standard calls to memory protection functions.