Back to results

Suspicious WSL Binary Hijack via Proxy Execution

Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations. When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry…

Description

Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations. When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry key and executes the wsl.exe found there. An attacker who modifies InstallLocation to a controlled path causes the stub to transparently proxy execution to a malicious payload, which then appears as a wsl.exe child of the legitimate System32 stub.

Detection logic

Detection requirements

Platform
ContainersESXiLinuxmacOSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
windows
Log source category
process_creation

Known benign triggers

  • Unlikely

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice