Windows Privilege Escalation via Token Impersonation Tools
Detects potential Windows privilege escalation attempts where a user account is assigned the SeImpersonatePrivilege and subsequently executes known exploitation tools (e.g., Potato-family exploits) within a short window. This pattern often indicates an attempt to escalate to SYSTEM privileges by abusing token impersonation vulnerabilities.
Microsoft Sentinel (KQL)

