WM_COPYDATA KernelCallbackTable Injection - VirtualAllocEx + WriteProcessMemory on GUI Process
Detects potential cross-process memory injection activity by monitoring for a non-debugger process that performs both NtAllocateVirtualMemory and WriteProcessMemory operations against a sensitive GUI target process within a short 5-minute correlation window.
Microsoft Sentinel (KQL)

