WSL Child Process Anomaly

 Original Source: [Sigma source]
Title: WSL Child Process Anomaly
Status: test
Description:Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/
  -https://twitter.com/nas_bench/status/1535431474429808642
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-23
modified:2023-08-15
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\wsl.exe'
      -'\wslhost.exe'

  selection_children_images:
    Image|endswith:
      -'\calc.exe'
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wscript.exe'

  selection_children_paths:
    Image|contains:
      -'\AppData\Local\Temp\'
      -'C:\Users\Public\'
      -'C:\Windows\Temp\'
      -'C:\Temp\'
      -'\Downloads\'
      -'\Desktop\'

  condition:selection_parent and 1 of selection_children_*
Falsepositives:
  -Unknown
Level: medium