Windows

Wsl.exeWsl.exe

Platform
Windows
Abuse functions
5
Mapped techniques
3

Description

Wsl.exe is a Windows living-off-the-land binary catalogued by the LOLBAS Project. Documented abuse functions: Execute, Download. Mapped ATT&CK techniques (per LOLBAS / GTFOBins → MITRE crosswalk): T1105, T1218. Defenders should monitor execution of Wsl.exe under non-administrative or sudo contexts and alert when its arguments match the abuse-function signatures.

Abuse functions· 5

ExecuteT1202

Performs execution of specified file, can be used to execute arbitrary Linux commands.

ExecuteT1202

Performs execution of arbitrary Linux commands as root without need for password.

ExecuteT1202

Performs execution of arbitrary Linux commands.

DownloadT1105

Download file

ExecuteT1218

Execute a payload as a child process of `bash.exe` while masquerading as WSL.

MITRE ATT&CK techniques· 3

T1202T1105T1218

Uses3

TypeTargetConfidenceTier
TechniqueIndirect Command Executiont1202100%live
TechniqueIngress Tool Transfert1105100%live
TechniqueSystem Binary Proxy Executiont1218100%live

Abuses2

TypeTargetConfidenceTier
TechniqueIngress Tool Transfert110585%live
TechniqueSystem Binary Proxy Executiont121885%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

LOLbin
wt.exe
LOLbin
Wab.exe
LOLbin
winfile.exe
LOLbin
Wscript.exe
LOLbin
Wfc.exe
LOLbin
Bash.exe
Sourced from LOLBAS Project. Curated by Adam Lundqvist, SQUR.