BIOC Informational

WSL Feature Installation

Detecting installation of Windows Subsystem for Linux feature.

Module:
Platform Analytics
Agent event type:
File
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indirect Command Execution (T1202)
Indicator:

File file name = *.vhdx.gz AND file path = *_microsoft-windows-lxss-vm-mode_* AND action type = create Process initiated by = TiWorker.exe , cgo name = TiWorker.exe , os parent name = TiWorker.exe

Preventable: yes