Token Impersonation and SeDebugPrivilege Abuse Targeting SYSTEM Processes
Detects unsigned or non-Microsoft processes attempting to access sensitive system process memory (lsass.exe, winlogon.exe, services.exe) or processes attempting to enable SeDebugPrivilege, which are common indicators of credential dumping or process injection attempts.
SentinelOne

