Token privilege stripping with Untrusted integrity level via SetTokenInformation
This rule detects attempts to manipulate process access tokens using the Windows 'SetTokenInformation' API. Specifically, it monitors for adjustments to token privileges or integrity levels, or the presence of 'Untrusted' markers. These behaviors are often indicative of an adversary attempting to bypass Windows access controls, perform token manipulation, or conduct privilege escalation.
Microsoft Sentinel (KQL)

