Suspicious Windows Token Manipulation APIs Invoked from Scripting Engines

This rule detects processes invoking sensitive Windows API functions related to token manipulation (such as DuplicateToken, ImpersonateLoggedOnUser, or CreateProcessAsUser) when initiated by suspicious parent processes like PowerShell, CMD, or WScript. It uses a scoring system that increases risk if the execution occurs from common non-standard directories (e.g., Temp, Public) or is associated with non-system account contexts.