CVE-2026-24294 NTLM Reflection Bypass - Privileged SMB Client Loopback Connection
Detects network connection attempts or successes from critical Windows processes (System, svchost.exe, lsass.exe) targeting the localhost interface (127.0.0.1 or ::1) on non-standard ports (above 1024, excluding SMB ports 445/139). This behavior is often indicative of local process injection, credential dumping activity, or unauthorized inter-process communication used by malware to bypass network security controls.
Microsoft Sentinel (KQL)

