CVE-2026-24294 EFS RPC Coercion Tool Targeting Localhost

Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.