Monitoring Process Creation via the Kernel (Part II) - Synack