WSL2 vmmem Process Suspicious External Network Connection via Sysmon
Detects outbound network connections originating from the 'vmmem' process, which is the Windows host process managing the WSL2 virtual machine. Since WSL2 operates with its own network stack, connections from this process to non-local (non-RFC-1918) IP addresses can bypass traditional Windows host-based network telemetry, potentially indicating command-and-control (C2) activity or payload staging occurring within the WSL2 container environment.
Sigma

