APT36 SHEET#CREEP: Diplomatic ISO Mount Followed by LNK-Spawned Dropper Execution
Detects the mounting of an ISO file, particularly those with diplomatic lure filenames, followed by the execution of an executable from a newly mounted optical or removable drive. This sequence of events is indicative of an attacker using a malicious ISO to deliver and execute malware.
Microsoft Sentinel (KQL)

