Skip to content

Commit b9a91bb

Browse files
Merge PR #5690 from @swachchhanda000 - fix: wsl fp on system execution anomaly detection
fix: System File Execution Location Anomaly - add filter for wsl fps
1 parent f6c5c4f commit b9a91bb

File tree

1 file changed

+9
-3
lines changed

1 file changed

+9
-3
lines changed

rules/windows/process_creation/proc_creation_win_susp_system_exe_anomaly.yml

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ references:
1212
- https://www.splunk.com/en_us/blog/security/inno-setup-malware-redline-stealer-campaign.html
1313
author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems)
1414
date: 2017-11-27
15-
modified: 2025-10-07
15+
modified: 2025-10-13
1616
tags:
1717
- attack.defense-evasion
1818
- attack.t1036
@@ -91,8 +91,14 @@ detection:
9191
- 'C:\Program Files\WindowsApps\Microsoft.PowerShellPreview'
9292
- '\AppData\Local\Microsoft\WindowsApps\Microsoft.PowerShellPreview' # pwsh installed from Microsoft Store
9393
Image|endswith: '\pwsh.exe'
94-
filter_main_wsl_windowsapps:
95-
Image|startswith: 'C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux'
94+
filter_main_wsl_programfiles:
95+
Image|startswith:
96+
- 'C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux'
97+
- 'C:\Program Files\WSL\'
98+
Image|endswith: '\wsl.exe'
99+
filter_main_wsl_appdata:
100+
Image|startswith: C:\Users\'
101+
Image|contains: '\AppData\Local\Microsoft\WindowsApps\'
96102
Image|endswith: '\wsl.exe'
97103
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
98104
falsepositives:

0 commit comments

Comments
 (0)