cmd.exe or powershell.exe spawned by wsl.exe via WSL interop
Detects instances where the Windows Subsystem for Linux (WSL) process spawns a Windows command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is often used to execute native Windows commands from within a Linux environment, potentially as a technique for stealthy command execution or to bypass traditional Windows-based monitoring and security controls.
Splunk (SPL)

