@tiraniddo I guess this is what happened:
- You created NtApiDotNet and used it in dozens of PoCs submitted to MSRC
- Defender team was tasked with creating detection for your PoCs, and the easiest way was to detect the use of NtApiDotNet, since it was mainly used for exploitation?