Windows Process Creation: Masqueraded wsl.exe Execution

Flags process launches masquerading as wsl.exe by matching Image path suffix while excluding legitimate OriginalFileName values.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03
title: "Windows Process Creation: Masqueraded wsl.exe Execution"
id: 5e23a277-8c26-4cca-982d-01300661be24
status: experimental
description: This rule identifies process executions where the image filename ends with \wsl.exe, excluding cases whose OriginalFileName matches wsl.exe or is null. Masquerading a malicious binary as wsl.exe can bypass image-name-only defenses and leverage user trust in the Windows Subsystem for Linux executable. It relies on process creation telemetry, specifically the process Image path and OriginalFileName metadata.
references:
  - https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
  - https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
  - https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
  - https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
  - https://learn.microsoft.com/en-us/windows/wsl/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_masquerading.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-05-05
tags:
  - attack.stealth
  - attack.t1036.005
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: \wsl.exe
  filter_main_legit_original:
    OriginalFileName: wsl.exe
  filter_main_null:
    OriginalFileName: null
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_wsl_masquerading/info.yml
license: DRL-1.1
related:
  - id: 530576ee-3b62-4bce-9a03-9aac6c61788a
    type: derived