PIVOTPIPE token impersonation (cmd 31) followed by RevertToSelf (cmd 28)

Detects a specific pattern of Windows API calls consistent with PIVOTPIPE C2 activity, involving process token impersonation (OpenProcessToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken) followed by a RevertToSelf call. The rule correlates these events within a single process, identifies artifacts related to PIVOTPIPE loader/payloads, and ensures the sequence completes within a short time window.