DEF CON 34 – Bocheng Xiang, HeeChan Kim – Reliable Windows LPE via chained logical bugs — token/impersonation anomaly
This rule detects command-line activity that references sensitive Windows API functions or privileges associated with token manipulation and process privilege escalation, such as SeDebugPrivilege, SeImpersonatePrivilege, DuplicateTokenEx, CreateProcessWithTokenW, and NtSetInformationToken. The rule excludes common service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to focus on potentially unauthorized use by standard or administrative accounts.
Microsoft Sentinel (KQL)

