MovieReaper EtwpCreateEtwThread Shellcode Execution via ntdll

Detects suspicious thread injection activities (CreateRemoteThreadApiCall, NtCreateThreadEx, or RtlCreateThread) or the loading of 'ntdll.dll' by specific potentially unauthorized binaries (e.g., RuntimeSSH.exe, smqdservice.exe, etc.) or within the 'ProgramData\Microsoft\Windows\Telemetry' directory. This often indicates reflective code injection or process tampering, excluding known legitimate Windows system processes.