This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential WSL Binary Modification from Installed Location
Original Source:
[Sigma source]
Title:
Potential WSL Binary Modification from Installed Location
Status:
experimental
Description:
Detects the modification of the wsl.exe binary from its installed location. Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
References:
-https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
-https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
-https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
-https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
-https://learn.microsoft.com/en-us/windows/wsl/
Author:
Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2026-05-05
modified:
None
Tags:
-'attack.stealth'
-'attack.t1036.005'
-'attack.t1218'
Logsource:
category: file_event
product: windows
Detection:
selection_wsl_exe:
TargetFilename|endswith
:
'\wsl.exe'
selection_wsl_folder:
- TargetFilename|contains
:
- ':\Program files\wsl\'
- ':\Program files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_'
- TargetFilename|contains|all
:
- ':\Users\'
- '\AppData\Local\Microsoft\WindowsApps\'
filter_main_msiexec:
Image
:
-'C:\Windows\System32\msiexec.exe'
-'C:\Windows\SysWOW64\msiexec.exe'
filter_main_svchost:
Image
:
'C:\Windows\System32\svchost.exe'
TargetFilename|contains
:
'\WindowsApps\'
condition
:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Unlikely
Level:
medium