Lately I've been thinking about the usefulness of ntdll.dll and the appearance of more and more proofs of concept that use this dll to bypass EDR's and AV's. Although it is a DLL with little documentation, it remains a strong candidate. In your opinion, should malware development focus on this DLL? (obviously all dll's are important for malware development, what I mean by this is, use ntdll.dll more).