Privilege escalation via token manipulation indicators
Detects execution of processes that reference suspicious Windows API functions related to token manipulation or process injection, specifically when initiated by critical system processes like svchost.exe or lsass.exe. This activity often indicates attempts at credential access or privilege escalation.
Microsoft Sentinel (KQL)

