Potential Direct Syscall of NtOpenProcess — Detection Rule

Detects potential calls to NtOpenProcess directly from NTDLL.

Read the full analysis on IntelFusions