Suspicious Windows Subsystem for Linux (WSL) Activity

This rule monitors for potentially malicious use of Windows Subsystem for Linux (WSL) binaries. It detects the execution of common command-line tools for reconnaissance, download, or lateral movement within the WSL environment, identifies the use of WSL to execute Windows 'living-off-the-land' binaries (Lolbins), and flags the installation of WSL components.