WSL InstallLocation Registry Key Modification on Windows

Alerts on suspicious registry modifications to the WSL InstallLocation key while excluding known legitimate MSI/WSL locations.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-05-05
Updated
2026-10-03

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags registry writes targeting the WSL InstallLocation path segment (\Lxss\MSI\InstallLocation). Changing this value may be used to redirect how WSL-related components locate their installation content, enabling execution redirection and defense-evasion. It relies on registry set telemetry that records the TargetObject being modified and filters out changes made by installer activity or common legitimate WSL paths.

Related detections9 linkedT1112 — drag to rearrange
Windows Process Creation: Suspicious reg.exe or PowerShell Editing of WSL InstallLocation Registry
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Malicious Windows Defender Service Disable via Registry
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation
Malicious WDigest UseLogonCredential Enablement for Cleartext Credentials
Suspicious RDP Enablement via fDenyTSConnections Registry Modification [Huntress] #2
Suspicious File Download via certutil urlcache
Suspicious Reconnaissance Spawned by wuauclt
WSL InstallLocation Registry Key Modification on Windows
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.