Monitoring Process Creation via the Kernel (Part I) - Synack