CVE-2026-24294 NTLM Reflection Bypass via Loopback Network Logon
Detects network logon events (Logon Type 3) using NTLM authentication where the source IP address is local (127.0.0.1 or ::1). This behavior can be indicative of attempts to interact with local services or perform lateral movement within the same host using credential-based techniques such as 'Pass-the-Hash' or unauthorized access to local resources.
Splunk (SPL)

