CVE-2026-24294 NTLM Reflection - net.exe tcpport SMB Mount

Detects the execution of net.exe or net1.exe with the 'tcpport' argument, which is typically used for querying network port connectivity or information on a host.