CVE-2026-24294 NTLM Reflection - Outbound SMB on Non-Standard Port to Internal/Loopback
Detects network connection attempts directed toward RFC 1918 private IP address spaces (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost (127.0.0.0/8) that do not involve common Windows file sharing ports (TCP/445 and TCP/139). This behavior may indicate lateral movement, internal reconnaissance, or the use of non-standard protocols for internal communication.
SentinelOne

