Detection & mitigation
Monitor for suspicious syscall patterns (e.g., direct syscalls from non-standard modules), ntdll unhooking (e.g., changes to ntdll memory), and unusual network traffic (DNS/ICMP tunneling). Deploy EDR with kernel-level visibility and behavioral detection, and keep systems patched.