heroui logo

Suspicious WSL Binary Masquerading

Sigma Rules

View Source
Summary
This rule detects masquerading attempts where a malicious binary tries to appear as the legitimate Windows Subsystem for Linux (WSL) executable (wsl.exe). It correlates process creation data with file metadata to identify cases where the process image path ends with \\wsl.exe but the OriginalFileName in the PE metadata is not the expected value. The legitimate WSL binary typically has OriginalFileName set to wsl.exe; masqueraded samples may have a different OriginalFileName, or a non-null value that indicates a mismatch. The rule triggers on such mismatches to flag potential binary name spoofing (T1036.005) and aligns with broader proxy/marshal techniques (T1218). It is marked high severity with low expected false positives, reflecting the suspicious nature of a wsl.exe masquerade, and includes regression test data and references for validation.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
  • Image
  • File
Created: 2026-05-05