VLC RTSP outbound connection possibly exploiting CVE-2026-73324
Detects outbound network connections initiated by the VLC media player (vlc.exe) to public IP addresses using the RTSP protocol (port 554) or referencing common media file extensions (e.g., .m3u, .xspf) in the command line. This behavior is often associated with remote stream retrieval or, in adversarial contexts, the potential use of media players to exfiltrate data or retrieve malicious remote payloads.
Microsoft Sentinel (KQL)

