BIOC
Informational
✕
Execution of WSL Distro
Detecting a new instance execution of Windows Subsystem for Linux distro.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Indirect Command Execution (T1202)
Indicator:
File file path = *\drivers\etc\hosts AND action type = read Process initiated by = wsl.exe AND os parent cmd = *LxssManager AND os parent name = svchost.exe
Preventable: yes