Access Token Manipulation via LSASS/Winlogon Handle Duplication (T1134)

Detects unauthorized attempts by processes to access the memory of sensitive Windows system processes, specifically LSASS.exe or winlogon.exe, using suspicious access masks associated with memory dumping or credential harvesting.