CVE-2026-24294 NTLM Relay Post-Auth SYSTEM Token Privilege Escalation

Detects potential token manipulation attacks using SMB loopback connections. The rule identifies processes executing with privileges commonly associated with token impersonation (SeImpersonatePrivilege, SeAssignPrimaryTokenPrivilege) or running as SYSTEM that are not expected system processes, correlated with an SMB network connection to the local loopback address on port 445.