CVE-2026-24294 NTLM Reflection - lsass.exe Loopback on Non-SMB Port
Detects unexpected network connections initiated by the Local Security Authority Subsystem Service (lsass.exe) to the localhost (127.0.0.1) on ports other than standard SMB ports (445 or 139). LSASS should typically only communicate locally via RPC or LPC for authentication services, and anomalous network activity from this process may indicate credential theft attempts, process injection, or unauthorized memory access activities.
SentinelOne

