CVE-2026-24294 NTLM Reflection - Impacket Relay and Coercion Tool Execution
This rule detects the execution of common Python-based network relay and exploitation tools such as Impacket's ntlmrelayx, smbserver.py, and PetitPotam. These tools are frequently utilized by adversaries to conduct NTLM relay attacks, perform remote service execution, or facilitate credential dumping.
SentinelOne

