Important Detection 2026 – Token Impersonation/Theft to SYSTEM Privilege

Detects the initiation of a new process where the effective user context is SYSTEM, but the originating process was launched by a non-privileged user account. This behavior is indicative of token manipulation techniques such as token impersonation or theft (e.g., via DuplicateTokenEx or ImpersonateLoggedOnUser) to escalate privileges to SYSTEM.