Windows Process Creation: wsl.exe Child Execution Outside Legitimate WSL Paths

Alert on System32 wsl.exe spawning a wsl.exe child process when the child path isn’t in known legitimate WSL locations.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags cases where C:\Windows\System32\wsl.exe spawns a child process running an executable that ends with \wsl.exe. It then excludes events where the child wsl.exe matches common legitimate WSL install locations and package/WinSxS paths. This behavior matters because a modified WSL install path can cause proxy-style execution that still appears as wsl.exe activity from the expected System32 stub. The rule relies on Windows process creation telemetry with parent and image path fields.

Related detections9 linkedT1036.005 — drag to rearrange
Windows File Event: Possible Modification of wsl.exe from Installed Location
Windows Process Creation: Masqueraded wsl.exe Execution
Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Suspicious WerFault Masquerade Executing From Non-System Path Linked to Turla Snake
Suspicious MsMpEng Execution from Non-Standard Directory
Suspicious printfilterpipelinesvc.exe Executed from Non-System Path (via process_creation)
Malicious Scheduled Task Running svchost32 Proxy from Windows Temp
Malicious systemd-daemon Masquerading Binary Execution on Linux
Suspicious Svchost Execution from Non-System Path
Windows Process Creation: wsl.exe Child Execution Outside Legitimate WSL Paths
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.