Token duplication and CreateProcessAsUserA spawning synchost.exe from non-system path

Detects access-token duplication combined with CreateProcessAsUserA spawning the non-standard synchost.exe process outside System32 under a target interactive session.