BIOC Informational

Execution of WSL Distro

Detecting a new instance execution of Windows Subsystem for Linux distro.

Module:
Platform Analytics
Agent event type:
File
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indirect Command Execution (T1202)
Indicator:

File file path = *\drivers\etc\hosts AND action type = read Process initiated by = wsl.exe AND os parent cmd = *LxssManager AND os parent name = svchost.exe

Preventable: yes