Windows Process Creation: Masqueraded wsl.exe Execution
Flags process launches masquerading as wsl.exe by matching Image path suffix while excluding legitimate OriginalFileName values.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-05-05
- Updated
- 2026-10-03
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process executions where the image filename ends with \wsl.exe, excluding cases whose OriginalFileName matches wsl.exe or is null. Masquerading a malicious binary as wsl.exe can bypass image-name-only defenses and leverage user trust in the Windows Subsystem for Linux executable. It relies on process creation telemetry, specifically the process Image path and OriginalFileName metadata.
Reporting behind it
- cardinalops.comhttps://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- blog.qualys.comhttps://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- thehackernews.comhttps://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/wsl/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_masquerading.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Masqueraded wsl.exe Execution"
id: 5e23a277-8c26-4cca-982d-01300661be24
status: experimental
description: This rule identifies process executions where the image filename ends with \wsl.exe, excluding cases whose OriginalFileName matches wsl.exe or is null. Masquerading a malicious binary as wsl.exe can bypass image-name-only defenses and leverage user trust in the Windows Subsystem for Linux executable. It relies on process creation telemetry, specifically the process Image path and OriginalFileName metadata.
references:
- https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- https://learn.microsoft.com/en-us/windows/wsl/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_masquerading.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-05-05
tags:
- attack.stealth
- attack.t1036.005
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \wsl.exe
filter_main_legit_original:
OriginalFileName: wsl.exe
filter_main_null:
OriginalFileName: null
condition: selection and not 1 of filter_main_*
falsepositives:
- Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_wsl_masquerading/info.yml
license: DRL-1.1
related:
- id: 530576ee-3b62-4bce-9a03-9aac6c61788a
type: derived