Access Token Manipulation: SeDebug/SeImpersonate Privilege Use + Context Switch

This rule detects potential Windows token manipulation by correlating logon events containing sensitive privileges (SeDebugPrivilege/SeImpersonatePrivilege) with subsequent process creation events under a different user context within a short timeframe. It further validates the activity by incorporating Sysmon Event ID 10 alerts that identify process access patterns commonly associated with token duplication or impersonation techniques used in post-exploitation frameworks like Cobalt Strike.