Windows Process Creation: Masqueraded wsl.exe Execution

Flags process launches masquerading as wsl.exe by matching Image path suffix while excluding legitimate OriginalFileName values.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions where the image filename ends with \wsl.exe, excluding cases whose OriginalFileName matches wsl.exe or is null. Masquerading a malicious binary as wsl.exe can bypass image-name-only defenses and leverage user trust in the Windows Subsystem for Linux executable. It relies on process creation telemetry, specifically the process Image path and OriginalFileName metadata.

Related detections9 linkedT1036.005 — drag to rearrange
Windows File Event: Possible Modification of wsl.exe from Installed Location
Windows Process Creation: wsl.exe Child Execution Outside Legitimate WSL Paths
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Suspicious WerFault Masquerade Executing From Non-System Path Linked to Turla Snake
Suspicious MsMpEng Execution from Non-Standard Directory
Suspicious printfilterpipelinesvc.exe Executed from Non-System Path (via process_creation)
Malicious Scheduled Task Running svchost32 Proxy from Windows Temp
Malicious systemd-daemon Masquerading Binary Execution on Linux
Suspicious Svchost Execution from Non-System Path
Windows Process Creation: Masqueraded wsl.exe Execution
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.