MovieReaper EtwpCreateEtwThread Shellcode Execution via ntdll
Detects suspicious thread injection activities (CreateRemoteThreadApiCall, NtCreateThreadEx, or RtlCreateThread) or the loading of 'ntdll.dll' by specific potentially unauthorized binaries (e.g., RuntimeSSH.exe, smqdservice.exe, etc.) or within the 'ProgramData\Microsoft\Windows\Telemetry' directory. This often indicates reflective code injection or process tampering, excluding known legitimate Windows system processes.
Microsoft Sentinel (KQL)

