Elastic medium stable eql
Windows Subsystem for Linux Enabled via Dism Utility
Detects attempts to enable the Windows Subsystem for Linux using Microsoft Dism utility. Adversaries may enable and use WSL for Linux to avoid detection.
Detection Logic
process where host.os.type == "windows" and event.type : "start" and
(process.name : "Dism.exe" or ?process.pe.original_file_name == "DISM.EXE") and
process.command_line : "*Microsoft-Windows-Subsystem-Linux*" Field Validations
Loading…
Comments (0)
Loading comments...