CVE-2026-24294 NTLM Reflection: Rogue SMB Server via Python or smbserver on Non-Standard Port

Detects execution of Python interpreters used as an SMB server, specifically where the implementation is not using the standard SMB port (445). This behavior is often associated with the use of tools like Impacket's smbserver.py for lateral movement, staging, or data exfiltration, attempting to blend in by using non-standard ports.