WSL2 Interop Abuse - Suspicious Windows Process Spawned by wsl.exe
Detects the execution of suspicious Windows native processes spawned directly by wsl.exe. Attackers leverage WSL2 interop functionality to execute Windows-native binaries from within a Linux environment, using the wsl.exe process tree to obscure their activities and stage payloads.
Sigma

