Potential WSL Binary Modification from Installed Location
Description
Detects the modification of the wsl.exe binary from its installed location. Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
Query · sigma
selection_wsl_exe: TargetFilename|endswith: \wsl.exe selection_wsl_folder: - TargetFilename|contains: - :\Program files\wsl\ - :\Program files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_ - TargetFilename|contains|all: - :\Users\ - \AppData\Local\Microsoft\WindowsApps\ filter_main_msiexec: Image: - C:\Windows\System32\msiexec.exe - C:\Windows\SysWOW64\msiexec.exe filter_main_svchost: Image: C:\Windows\System32\svchost.exe TargetFilename|contains: \WindowsApps\ condition: all of selection_* and not 1 of filter_main_*
Known false positives
- Unlikely