CVE-2026-24294 PetitPotam NTLM Coercion Tool Execution via Sysmon

Detects command-line activity indicative of the PetitPotam exploit or general EFSRPC (Encrypting File System Remote Protocol) coercion attempts. Adversaries use these techniques to force a machine to authenticate against another system (e.g., a domain controller), typically as a precursor to NTLM relay attacks.