Token Impersonation via Non-SYSTEM Process Spawning SYSTEM Child (T1134.001)
Detects instances where a non-SYSTEM parent process spawns a child process running as SYSTEM, characteristic of 'Potato' family exploits (e.g., JuicyPotato, PrintSpoofer) leveraging SeImpersonatePrivilege to elevate privileges. The rule specifically filters for known legitimate SYSTEM process spawners while highlighting suspicious parent-child process relationships.
Microsoft Sentinel (KQL)

