C2Looper v2 process injection via winspool.drv module
Detects instances where the Windows spooler driver (winspool.drv) is loaded by a process that subsequently performs suspicious memory operations typical of process injection (e.g., CreateRemoteThreadApiCall, WriteToProcessMemory, ProcessInjection) within a 5-minute window.
Microsoft Sentinel (KQL)

