Back to results

Potential WSL InstallLocation Registry Key Modification

Detects modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key. Attackers can modify this registry key to redirect the execution flow of legitimate WSL processes (wsl.exe or bash.exe) to…

Description

Detects modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key. Attackers can modify this registry key to redirect the execution flow of legitimate WSL processes (wsl.exe or bash.exe) to a malicious payload, acting as a proxy execution and defense evasion technique.

Detection logic

Detection requirements

Platform
LinuxmacOSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source product
windows
Log source category
registry_set

Known benign triggers

  • Unlikely

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice