Suspicious WSL InstallLocation Registry Key Modification Via CommandLine
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments. Legitimate modifications to this key are performed exclusively by the Windows Installer…
Description
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments. Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update. Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
Detection logic
Detection requirements
- Platform
- LinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- windows
- Log source category
- process_creation
Known benign triggers
- Unlikely
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2 | 5 |
| cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/ | 5 |
| learn.microsoft.com/en-us/windows/wsl/ | 5 |
| thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html | 5 |
| www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/ | 5 |
From the source
- At source
- Open at source
- Upstream identifier
- f9f62824-de4e-40ca-afe7-8358f76a876d
- Tagged by the source as
- attack.defense-impairmentattack.persistenceattack.stealth
Licence
- Published under
- Detection Rule License 1.1Read the licence
- Attribution
- Required
Authorship
- Published
- Oct 3, 2026
- Version
- 1