Skip to content

Wsl rules#5668

Open
Liran017 wants to merge 9 commits into
SigmaHQ:masterfrom
Liran017:WSL-rules
Open

Wsl rules#5668
Liran017 wants to merge 9 commits into
SigmaHQ:masterfrom
Liran017:WSL-rules

Conversation

@Liran017

@Liran017 Liran017 commented Oct 1, 2025

Copy link
Copy Markdown
Contributor

Summary of the Pull Request

This PR includes new rules that are related to WSL in Windows.

The full breakdown can be found here:
https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/.

Changelog

new: WSL Binary Modification from Installed Location
new: WSL Binary Hijack via Proxy Execution
new: WSL InstallLocation Registry Key Modification Via CommandLine
new: WSL Binary Masquerading
new: WSL InstallLocation Registry Key Modification

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions Bot added Rules Windows Pull request add/update windows related rules labels Oct 1, 2025
Comment thread rules/windows/file/file_event/file_event_win_wsl_binary_modification.yml Outdated
@swachchhanda000 swachchhanda000 added Author Input Required changes the require information from original author of the rules Additional Data Needed labels Oct 9, 2025
@nasbench nasbench self-requested a review December 24, 2025 16:52

@swachchhanda000 swachchhanda000 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HI @Liran017,

I apologize for the delayed response on this pull request.

I have again reviewed some changes you made and there are still some questions/suggestions your way before we can approve this PR.

Thank you for your patience and effort on this PR.

Comment thread rules/windows/file/file_event/file_event_win_wsl_binary_modification.yml Outdated
swachchhanda000 and others added 3 commits May 5, 2026 09:20
Co-Authored-By: Liran Ravich <61919718+Liran017@users.noreply.github.com>
Co-Authored-By: Liran Ravich <61919718+Liran017@users.noreply.github.com>
Co-Authored-By: Liran Ravich <61919718+Liran017@users.noreply.github.com>
@swachchhanda000 swachchhanda000 removed Author Input Required changes the require information from original author of the rules Additional Data Needed labels May 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants