CVE-2026-24294 NTLM Reflection - LSASS/Svchost Loopback SMB on Non-Standard Port
Detects instances where privileged system processes such as lsass.exe or svchost.exe attempt a network connection to the local loopback address on ports other than standard SMB ports (445, 139). This pattern is indicative of potential coercion or relay attacks, specifically targeting the authentication mechanisms of these services to an attacker-controlled SMB server.
Microsoft Sentinel (KQL)

