see uploaded images
"A new process was suspiciously created with a
duplicated access token for the SYSTEM account.
This activity, often referred to as _token
impersonation_, is used to elevate privileges for
existing processes or start processes with elevated
privileges"