ETW Tamper Patch: EtwEventWrite/ntdll.dll Buffer Modification

Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.