
Summary
This rule detects unauthorized modifications to the Windows Subsystem for Linux (WSL) InstallLocation registry key, a technique attackers can use to hijack the execution flow of WSL binaries (such as wsl.exe or bash.exe). By altering InstallLocation, an adversary can redirect legitimate WSL processes to a malicious payload, enabling proxy execution and defense evasion. The rule looks for registry targets containing the path "\Lxss\MSI\InstallLocation" and applies exclusions to ensure the modification isn’t simply pointing to known legitimate WSL binaries or MSI install flows. Specifically, it flags when the registry value points to a location outside legitimate binaries (e.g., outside C:\Program Files\WSL or %ProgramFiles%\WSL) and not through standard MSI installer paths (msiexec.exe). This combination indicates potential persistence and stealthy proxy execution for WSL-related components. The detection is categorized under Windows Registry monitoring and is aligned with techniques to modify registry keys for privilege persistence and evasion. The rule is marked experimental and includes a false-positive note of being unlikely in typical environments. MITRE mappings include T1112 (Modify Registry) and T1218 (System Binary Proxy Execution). The rule would help SOCs and EDRs identify anomalous attempts to hijack WSL binaries for malicious payloads and stealthy execution. The associated references discuss WSL hijacking, proxy execution, and relevant defenses. The rule self-documents as a registry_set event targeting Windows, with a focus on WSL-related install path integrity.
Categories
- Windows
Data Sources
- Windows Registry
Created: 2026-05-05