BIOC
Informational
✕
WSL Feature Installation
Detecting installation of Windows Subsystem for Linux feature.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indirect Command Execution (T1202)
Indicator:
File file name = *.vhdx.gz AND file path = *_microsoft-windows-lxss-vm-mode_* AND action type = create Process initiated by = TiWorker.exe , cgo name = TiWorker.exe , os parent name = TiWorker.exe
Preventable: yes