CVE-2026-24294 NTLM Relay - SYSTEM Shell Spawn After SMB Connection
Detects instances where a process running under the NT AUTHORITY\SYSTEM user context spawns a common execution utility (like cmd, powershell, or wscript) on a host that has recently engaged in network communication over port 445 (SMB). This behavior is highly indicative of lateral movement using SMB, such as service-based execution or remote command execution via tools like PsExec or WMI.
SentinelOne

