Most Popular Detection 2026: Suspicious ISO and LNK Container Execution from Phi
Detects user-initiated execution of scripts or binaries directly from the root of a drive letter. This pattern is commonly associated with phishing campaigns delivering malicious payloads via mounted ISO or IMG files, which allow attackers to bypass mark-of-the-web or macro security controls.
SentinelOne

