Best Detection of 2026 Series: ISO/IMG Container Delivery - LNK/EXE Execution Post-Mount Bypassing MOTW
Detects the creation or writing of disk image files (.iso, .img, .vhd, .vhdx) followed by the execution of suspicious file types (.lnk, .exe, .js, .vbs, .cmd, .bat, .scr) by explorer.exe within a 10-minute window. This behavior is indicative of an adversary using container files to bypass security controls or execute malicious payloads from mounted images.
Cortex XDR

