
Summary
Detects potential modification of the WSL binary by monitoring Windows file events for the WSL executable (wsl.exe) being loaded from its installed location. The rule triggers when a file event shows a wsl.exe target and the path resides in standard WSL installation directories (Program Files/Wsl or WindowsApps/MicrosoftCorporationII.WindowsSubsystemForLinux_) or in user contexts (Users/<user>/AppData/Local/Microsoft/WindowsApps). It excludes legitimate MSI installer or svchost wrappers that load from WindowsApps to reduce false positives. The condition requires all of the selection criteria and not any of the filter criteria. This pattern could indicate an attacker replacing the legitimate wsl.exe with a malicious payload to proxy execution and evade defenses. The rule is labeled experimental, uses Windows File events, and references TTPs Masquerading (T1036.005) and Proxy Execution (T1218).
Categories
- Endpoint
- Windows
Data Sources
- File
Created: 2026-05-05