Suspicious WSL Binary Hijack via Proxy Execution
Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations. When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry…
Description
Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations. When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry key and executes the wsl.exe found there. An attacker who modifies InstallLocation to a controlled path causes the stub to transparently proxy execution to a malicious payload, which then appears as a wsl.exe child of the legitimate System32 stub.
Detection logic
Detection requirements
- Platform
- ContainersESXiLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- windows
- Log source category
- process_creation
Known benign triggers
- Unlikely
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2 | 5 |
| cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/ | 5 |
| learn.microsoft.com/en-us/windows/wsl/ | 5 |
| thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html | 5 |
| www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/ | 5 |
From the source
- At source
- Open at source
- Upstream identifier
- 88d306e9-8e2d-4025-9768-28757d2732db
- Tagged by the source as
- attack.stealth
Licence
- Published under
- Detection Rule License 1.1Read the licence
- Attribution
- Required
Authorship
- Published
- Oct 3, 2026
- Version
- 1