Potential WSL Binary Modification from Installed Location
Detects the modification of the wsl.exe binary from its installed location. Attackers can replace the legitimate wsl.exe binary with a malicious payload in its place, which is then executed when the user runs WSL, acting as a proxy execution and defense evasion technique.
Sigma

