CVE-2026-24294 NTLM Reflection Bypass via net.exe Local SMB Mount
Detects the use of the 'net.exe' or 'net1.exe' command-line utilities to mount a local SMB share using loopback addresses (127.0.0.1 or localhost) with the '/tcpport' argument. This pattern is indicative of attempts to exploit CVE-2026-24294 to bypass NTLM authentication protections through local reflection or relay attacks.
Microsoft Sentinel (KQL)

