Token Impersonation via runas.exe /savecred or Token Abuse (T1134.001)

Detects potentially malicious process execution behaviors, including the use of 'runas.exe' with saved credentials, the execution of 'runas.exe' by unauthorized users, and unauthorized cross-process access to sensitive Windows system processes such as lsass.exe, winlogon.exe, or services.exe, which are common indicators of credential access or privilege escalation attempts.