WriteProcessMemory Monitor is designed to monitor processes in your system that write to other process' virtual address spaces. Malware often uses such techniques in order to write payload stubs to a foreign process to hook an API, load a malware DLL, etc. The NtWriteVirtualMemory function of ntdll.dll is hooked in order to achieve the desired logging functionality.