drop process token map · detect non-system process running with system token · runs locally
SYSTEM token on user shell · SeDebugPrivilege · integrity level mismatch
heuristic screener · parses exports locally · not definitive proof