CVE-2026-24294 NTLM Reflection Bypass via net.exe Non-Standard TCPPort

This rule detects the use of 'net.exe' or 'net1.exe' to configure a non-standard SMB port, which is a technique often used for NTLM reflection and relay attacks. By specifying an arbitrary port for SMB traffic, an attacker may attempt to bypass standard network filtering or establish a listener to intercept authentication requests.