Windows Process Creation: Suspicious reg.exe or PowerShell Editing of WSL InstallLocation Registry
Flags reg.exe or PowerShell command lines editing the WSL InstallLocation registry value under Lxss MSI.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-05-05
- Updated
- 2026-10-03
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies command-line use of reg.exe or PowerShell to modify the WSL InstallLocation registry value under the Lxss MSI path. Attackers may leverage this to redirect how WSL executes, enabling stealthy persistence or defense-impairment by pointing WSL to attacker-controlled binaries. It relies on Windows process creation telemetry capturing the Image/OriginalFileName and the presence of specific command-line arguments indicating registry modification actions targeting InstallLocation.
Reporting behind it
- cardinalops.comhttps://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- blog.qualys.comhttps://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- thehackernews.comhttps://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/wsl/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_installlocation_modification_via_cmdline.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Suspicious reg.exe or PowerShell Editing of WSL InstallLocation Registry"
id: 0b040b73-feea-41d1-9cb9-db104cb28920
related:
- id: 83475063-b1c8-4774-9568-69bbda71a539
type: similar
- id: f9f62824-de4e-40ca-afe7-8358f76a876d
type: derived
status: experimental
description: This rule identifies command-line use of reg.exe or PowerShell to modify the WSL InstallLocation registry value under the Lxss MSI path. Attackers may leverage this to redirect how WSL executes, enabling stealthy persistence or defense-impairment by pointing WSL to attacker-controlled binaries. It relies on Windows process creation telemetry capturing the Image/OriginalFileName and the presence of specific command-line arguments indicating registry modification actions targeting InstallLocation.
references:
- https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- https://learn.microsoft.com/en-us/windows/wsl/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_installlocation_modification_via_cmdline.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-05-05
tags:
- attack.stealth
- attack.defense-impairment
- attack.persistence
- attack.t1112
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \powershell.exe
- \pwsh.exe
- \reg.exe
- OriginalFileName:
- powershell.exe
- pwsh.dll
- reg.exe
selection_cli_action:
CommandLine|contains:
- " add "
- New-ItemProperty
- Set-ItemProperty
- "sp "
selection_cli_key:
CommandLine|contains:
- \Lxss\MSI
- /Lxss/MSI
selection_cli_value:
CommandLine|contains: InstallLocation
condition: all of selection_*
falsepositives:
- Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_wsl_installlocation_modification_via_cmdline/info.yml
license: DRL-1.1