CVE-2026-24294 LSASS Outbound Loopback NTLM Reflection via Sysmon
Detects instances where the Local Security Authority Subsystem Service (lsass.exe) initiates a network connection to the loopback address (127.0.0.1 or ::1), excluding standard SMB traffic (Port 445). Such behavior by LSASS is highly anomalous and may indicate exploitation attempts, such as memory dumping or credential harvesting techniques involving inter-process communication.
Splunk (SPL)

