Windows Process Creation: Suspicious reg.exe or PowerShell Editing of WSL InstallLocation Registry

Flags reg.exe or PowerShell command lines editing the WSL InstallLocation registry value under Lxss MSI.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03
title: "Windows Process Creation: Suspicious reg.exe or PowerShell Editing of WSL InstallLocation Registry"
id: 0b040b73-feea-41d1-9cb9-db104cb28920
related:
  - id: 83475063-b1c8-4774-9568-69bbda71a539
    type: similar
  - id: f9f62824-de4e-40ca-afe7-8358f76a876d
    type: derived
status: experimental
description: This rule identifies command-line use of reg.exe or PowerShell to modify the WSL InstallLocation registry value under the Lxss MSI path. Attackers may leverage this to redirect how WSL executes, enabling stealthy persistence or defense-impairment by pointing WSL to attacker-controlled binaries. It relies on Windows process creation telemetry capturing the Image/OriginalFileName and the presence of specific command-line arguments indicating registry modification actions targeting InstallLocation.
references:
  - https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
  - https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
  - https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
  - https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
  - https://learn.microsoft.com/en-us/windows/wsl/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wsl_installlocation_modification_via_cmdline.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-05-05
tags:
  - attack.stealth
  - attack.defense-impairment
  - attack.persistence
  - attack.t1112
  - attack.t1218
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
        - \reg.exe
    - OriginalFileName:
        - powershell.exe
        - pwsh.dll
        - reg.exe
  selection_cli_action:
    CommandLine|contains:
      - " add "
      - New-ItemProperty
      - Set-ItemProperty
      - "sp "
  selection_cli_key:
    CommandLine|contains:
      - \Lxss\MSI
      - /Lxss/MSI
  selection_cli_value:
    CommandLine|contains: InstallLocation
  condition: all of selection_*
falsepositives:
  - Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_wsl_installlocation_modification_via_cmdline/info.yml
license: DRL-1.1