Potential WSL Binary Modification from Installed Location


Description

Detects the modification of the wsl.exe binary from its installed location. Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.

Query · sigma

selection_wsl_exe:
  TargetFilename|endswith: \wsl.exe
selection_wsl_folder:
- TargetFilename|contains:
  - :\Program files\wsl\
  - :\Program files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_
- TargetFilename|contains|all:
  - :\Users\
  - \AppData\Local\Microsoft\WindowsApps\
filter_main_msiexec:
  Image:
  - C:\Windows\System32\msiexec.exe
  - C:\Windows\SysWOW64\msiexec.exe
filter_main_svchost:
  Image: C:\Windows\System32\svchost.exe
  TargetFilename|contains: \WindowsApps\
condition: all of selection_* and not 1 of filter_main_*

Known false positives

  • Unlikely
Raw source Potential WSL Binary Modification from Installed Location · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potential WSL Binary Modification from Installed Location
id: 2f400434-01e1-416b-b52c-bb5bfbb9eb78
status: experimental
description: |
    Detects the modification of the wsl.exe binary from its installed location.
    Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
references:
    - https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
    - https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
    - https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
    - https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
    - https://learn.microsoft.com/en-us/windows/wsl/
author: Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-05-05
tags:
    - attack.stealth
    - attack.t1036.005
    - attack.t1218
logsource:
    category: file_event
    product: windows
detection:
    selection_wsl_exe:
        TargetFilename|endswith: '\wsl.exe'
    selection_wsl_folder:
        - TargetFilename|contains:
              - ':\Program files\wsl\'
              - ':\Program files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_'
        - TargetFilename|contains|all:
              - ':\Users\'
              - '\AppData\Local\Microsoft\WindowsApps\'
    filter_main_msiexec:
        Image:
            - 'C:\Windows\System32\msiexec.exe'
            - 'C:\Windows\SysWOW64\msiexec.exe'
    filter_main_svchost:
        Image: 'C:\Windows\System32\svchost.exe'
        TargetFilename|contains: '\WindowsApps\'
    condition: all of selection_* and not 1 of filter_main_*
falsepositives:
    - Unlikely
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_wsl_binary_modification/info.yml

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.