Important Detection 2026: Access Token Manipulation and Impersonation

Detects the use of token manipulation APIs (DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser), the 'runas' command for credential switching, or the execution of known security token manipulation tools (e.g., incognito, Tokenvator, Invoke-TokenManipulation). This activity is commonly associated with privilege escalation and token theft.