Suspicious WSL Binary Masquerading
Detects execution of masqueraded wsl.exe binary. Attackers can rename a malicious payload to wsl.exe to masquerade as the legitimate Windows Subsystem for Linux binary, bypassing detection based on image name alone…
Description
Detects execution of masqueraded wsl.exe binary. Attackers can rename a malicious payload to wsl.exe to masquerade as the legitimate Windows Subsystem for Linux binary, bypassing detection based on image name alone and abusing user trust in the WSL process name.
Detection logic
Detection requirements
- Platform
- ContainersESXiLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source product
- windows
- Log source category
- process_creation
Known benign triggers
- Unlikely
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2 | 5 |
| cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/ | 5 |
| learn.microsoft.com/en-us/windows/wsl/ | 5 |
| thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html | 5 |
| www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/ | 5 |
From the source
- At source
- Open at source
- Upstream identifier
- 530576ee-3b62-4bce-9a03-9aac6c61788a
- Tagged by the source as
- attack.stealth
Licence
- Published under
- Detection Rule License 1.1Read the licence
- Attribution
- Required
Authorship
- Published
- Oct 3, 2026
- Version
- 1