CVE-2026-24294 PetitPotam EFS RPC NTLM Coercion Process Execution
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
Microsoft Sentinel (KQL)

