heroui logo

Suspicious WSL Binary Hijack via Proxy Execution

Sigma Rules

View Source
Summary
Detects a suspicious Windows Subsystem for Linux (WSL) binary hijack where a child wsl.exe is spawned by a parent wsl.exe from outside legitimate WSL install locations. The WSL stub (System32\wsl.exe) locates the actual wsl.exe via the InstallLocation registry key; an attacker modifying InstallLocation to a controlled path can proxy execution to a malicious payload, causing a rogue wsl.exe to appear as a child of the legitimate stub. The rule triggers on Windows process_creation events where the ParentImage is wsl.exe and the Image ends with \wsl.exe, but only if the child Image does not reside in a known legitimate WSL path. Legitimate paths are enumerated as whitelists (system32 and Program Files locations; WinSxS and WindowsApps locations; and user/AppData WindowsApps locations). The condition “selection and not 1 of filter_main_*” yields a match when the child wsl.exe is not in any whitelisted path, indicating possible proxy execution or hijack. This mirrors MITRE techniques such as Masquerade (T1036.005) and Signed Binary Proxy Execution (T1218). The rule is categorized as high severity, Windows process_creation-based, and experimental. Regression and validation data are provided in the referenced repository.
Categories
  • Windows
  • Endpoint
Data Sources
  • Process
  • Image
Created: 2026-05-05