WSL InstallLocation Registry Key Modification on Windows
Alerts on suspicious registry modifications to the WSL InstallLocation key while excluding known legitimate MSI/WSL locations.
- Product
- windows
- Category
- registry_set
- Author
- Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2026-05-05
- Updated
- 2026-10-03
ATT&CK techniques
Persistence → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags registry writes targeting the WSL InstallLocation path segment (\Lxss\MSI\InstallLocation). Changing this value may be used to redirect how WSL-related components locate their installation content, enabling execution redirection and defense-evasion. It relies on registry set telemetry that records the TargetObject being modified and filters out changes made by installer activity or common legitimate WSL paths.
Reporting behind it
- cardinalops.comhttps://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- blog.qualys.comhttps://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- thehackernews.comhttps://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/wsl/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_wsl_installlocation_registry_key_modification.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: WSL InstallLocation Registry Key Modification on Windows
id: 6da773ed-864e-4264-9376-3760f080ece3
related:
- id: f9f62824-de4e-40ca-afe7-8358f76a876d
type: similar
- id: 83475063-b1c8-4774-9568-69bbda71a539
type: derived
status: experimental
description: This rule flags registry writes targeting the WSL InstallLocation path segment (\Lxss\MSI\InstallLocation). Changing this value may be used to redirect how WSL-related components locate their installation content, enabling execution redirection and defense-evasion. It relies on registry set telemetry that records the TargetObject being modified and filters out changes made by installer activity or common legitimate WSL paths.
references:
- https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/
- https://blog.qualys.com/vulnerabilities-threat-research/2022/04/20/implications-of-windows-subsystem-for-linux-for-adversaries-defenders-part-2
- https://www.bleepingcomputer.com/news/security/new-malware-uses-windows-subsystem-for-linux-for-stealthy-attacks/
- https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
- https://learn.microsoft.com/en-us/windows/wsl/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_wsl_installlocation_registry_key_modification.yml
author: Liran Ravich, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-05-05
tags:
- attack.stealth
- attack.defense-impairment
- attack.persistence
- attack.t1112
- attack.t1218
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: \Lxss\MSI\InstallLocation
filter_main_legitimate_binary:
- Details:
- C:\Program Files\WSL
- "%ProgramFiles%\\WSL"
- Details|contains:
- :\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_
- \AppData\Local\Microsoft\WindowsApps
- "%ProgramFiles%\\WindowsApps\\MicrosoftCorporationII.WindowsSubsystemForLinux_"
filter_main_msiexec:
Image:
- C:\Windows\System32\msiexec.exe
- C:\Windows\SysWOW64\msiexec.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unlikely
level: medium
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_wsl_installlocation_registry_key_modification/info.yml
license: DRL-1.1