b0156181e7
* New Rules] T1134 Access Token Manipulation 3 rules (2 compatible only with Elastic endpoint) and 1 generic one using winlogs. * Update privilege_escalation_tokenmanip_sedebugpriv_enabled.toml * fix ruleid * Update privilege_escalation_via_token_theft.toml * timestamp_override = "event.ingested" * Update non-ecs-schema.json * linted * Update privilege_escalation_tokenmanip_sedebugpriv_enabled.toml * Update non-ecs-schema.json Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>