Potential Token Impersonation/Theft via Command Line
This rule detects suspicious command-line activity indicative of potential token impersonation or theft. It specifically looks for the keywords 'token' or 'impersonate' within process creation command lines (EventID 4688) and triggers an alert if these keywords appear 3 or more times within an hour on the same computer by the same account. This could indicate an adversary attempting to manipulate access tokens to elevate privileges or operate under a different security context.
Microsoft Sentinel (KQL)

