CVE-2026-24294 NTLM Reflection Bypass: Loopback SMB on Non-Standard Port

Detects network connections originating from a process and directed towards the local loopback interface (127.0.0.1 or ::1) on non-privileged, non-SMB ports (>= 1024 and != 445). This pattern can identify inter-process communication (IPC) over local network sockets which may be used by malware or malicious scripts to bypass security controls or communicate with local services.