
Summary
Detects Windows process creations where reg.exe or PowerShell is used to modify the WSL (Windows Subsystem for Linux) InstallLocation registry key via command-line arguments. Legitimate modifications to this key are performed only by the Windows Installer (msiexec.exe) during WSL package installation or update. Manual or scripted edits using reg.exe or PowerShell to set this value strongly indicate an attempt to redirect WSL execution to a malicious binary. The rule triggers when a process image matches powershell.exe, pwsh.exe, or reg.exe and the command line contains registry actions (such as add, New-ItemProperty, Set-ItemProperty, or short form like sp) along with a registry path containing \Lxss\MSI (or /Lxss/MSI) and the InstallLocation value. This combination constitutes a high-severity indicator of potential registry-based hijacking of WSL. False positives are reported as unlikely, but legitimate administrative actions could resemble this pattern under rare circumstances. Mitigations include restricting non-administrator registry modifications, enabling credential guard and process whitelisting, and monitoring for unauthorized reg.exe/PowerShell activity aimed at WSL InstallLocation to prevent persistence or redirection attacks.
Categories
- Windows
- Endpoint
Data Sources
- Process
- Command
Created: 2026-05-05