Suspicious Sysmon as Execution Parent — Detection Rule

Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)

Read the full analysis on IntelFusions