Back to results

Suspicious WSL Binary Masquerading

Detects execution of masqueraded wsl.exe binary. Attackers can rename a malicious payload to wsl.exe to masquerade as the legitimate Windows Subsystem for Linux binary, bypassing detection based on image name alone…

Description

Detects execution of masqueraded wsl.exe binary. Attackers can rename a malicious payload to wsl.exe to masquerade as the legitimate Windows Subsystem for Linux binary, bypassing detection based on image name alone and abusing user trust in the WSL process name.

Detection logic

Detection requirements

Platform
ContainersESXiLinuxmacOSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
windows
Log source category
process_creation

Known benign triggers

  • Unlikely

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice