Windows File Event: Possible Modification of wsl.exe from Installed Location

Alerts on attempts to modify wsl.exe in installed WSL/WindowsApps locations, indicating potential binary replacement for proxy execution.

FreeReviewedSigma · Medium · v1
Product
windows
Category
file_event
Author
Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags file events where wsl.exe is targeted for modification from typical installed paths under Program Files and WindowsApps. Replacing the legitimate wsl.exe binary with a malicious one can lead to proxy execution when a user runs WSL, supporting stealth and defense evasion. It relies on Windows file event telemetry capturing the target filename and associated modifying process image, with exclusions for msiexec and svchost to reduce benign installer/service activity.

Related detections9 linkedT1036.005 — drag to rearrange
Windows Process Creation: Masqueraded wsl.exe Execution
Windows Process Creation: wsl.exe Child Execution Outside Legitimate WSL Paths
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Suspicious WerFault Masquerade Executing From Non-System Path Linked to Turla Snake
Suspicious MsMpEng Execution from Non-Standard Directory
Suspicious printfilterpipelinesvc.exe Executed from Non-System Path (via process_creation)
Malicious Scheduled Task Running svchost32 Proxy from Windows Temp
Malicious systemd-daemon Masquerading Binary Execution on Linux
Suspicious Svchost Execution from Non-System Path
Windows File Event: Possible Modification of wsl.exe from Installed Location
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.