WSL2 Payload Staging via wsl.exe Indirect Execution and DllHost.exe File Writes
This rule detects various activities related to the Windows Subsystem for Linux (WSL), specifically focusing on: 1) Executing network tools like curl or wget via wsl.exe, 2) The creation of executable or script files in suspicious directories (User\Public, ProgramData, Windows\Temp) by DllHost.exe, and 3) The execution of wsl.exe or wslhost.exe. These behaviors are often associated with adversaries using WSL to bypass security controls, stage payloads, or facilitate command-and-control communication.
Splunk (SPL)

