Activity from unhooked NTDLL module

Detects suspicious activity originating from an unhooked or manually mapped copy of NTDLL loaded into a process. This behavior is commonly associated with defense evasion frameworks that bypass user-mode API hooks implemented by security products.

Back to all rules