Token duplication and CreateProcessAsUserA spawning synchost.exe from non-system path
Detects access-token duplication combined with CreateProcessAsUserA spawning the non-standard synchost.exe process outside System32 under a target interactive session.
Microsoft Sentinel (KQL)

