wsl.exe

by Microsoft
Operating Systemmedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows Subsystem for Linux (wsl.exe) launches and manages Linux distributions running on Windows. It provides the interface between Windows and the WSL2 virtual machine, allowing users to run Linux commands and applications.

wsl.exe is the 95th most commonly executed Windows program in EchoTrail's dataset, observed 261,110 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by wsl.exe.

Get this in your tools

The same record for wsl.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/wsl.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

95th
most commonly executed Windows program
261,110
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3250.03%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.3.0_x64__8wekyb3d8bbwe25.79%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.3.0_x64__8wekyb3d8bbwe17.61%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.0.0_x64__8wekyb3d8bbwe5.86%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.6.0_x64__8wekyb3d8bbwe0.39%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.5.0_x64__8wekyb3d8bbwe0.13%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.0.0_x64__8wekyb3d8bbwe0.1%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_0.70.4.0_x64__8wekyb3d8bbwe0.09%

Top Hashes (SHA256)

  • 90711b2c90306034f4f9a2fb7cddcf1d514e64c435cbc1fc81003059c19a343d49.97%
  • 6b36f68114e03e647641b65282d9c14c57115fdc5bfaebf97d502c7c99848ed425.79%
  • 56187b1998193ddb24eed8c88f0fcc0ac03bf92865affa85667a2382626f625717.61%
  • 876d4aeb17118a5a55465da1501f8c7a1af5a6ac14712b5805205bfb317fac895.86%
  • 7e1cb7959028b4d16fc82af0b55f4bc759739bd6e4f43f29103d67cc8dd657780.39%
  • 36e9d37ba8b69207a794e8b6fbed30f368789ad82a96f67f87c72f8605a085000.13%
  • c814c244b636ab1a7c65ee12146b84241fc9485981a1fb09c3a1b449fe91ad480.1%
  • 67331b0dccbe70ced849c958a3c768b992a3ca8243328a858bbc7820e1a9357b0.09%
  • 9e724c5a8000dd595d6d278fbe85b6f043f35cb1acc77d71f5849975064d293f0.03%
  • f0556e52dd41e2a16cf273600492abe4a3d196634b9bd1426c8e6706b418d8620.02%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does wsl.exe normally do?

Located in C:\Windows\System32 or Windows Apps directory. Commonly launched by itself (recursive for WSL internals), Docker Desktop (com.docker.backend.exe), and VS Code (Code.exe). Spawns wslhost.exe and conhost.exe.

When is wsl.exe suspicious?

Launched by unexpected parents (Office applications, script interpreters). Used to execute commands that bypass Windows-native security controls (WSL Linux binaries are not subject to AppLocker or WDAC). Data exfiltration through WSL file system access (WSL can access the full Windows file system via /mnt/c/).

How do attackers abuse wsl.exe?

Security control bypass: WSL provides a Linux environment that may bypass Windows security tooling (AppLocker, AMSI, Defender). Attackers can download and execute Linux-native tools from within WSL. Cross-platform attack: WSL can access the full Windows file system, enabling data theft or modification from within the Linux environment without triggering Windows file monitoring. Defense evasion: Linux binaries executed within WSL may not be visible to Windows EDR tools.

Detection guidance

Medium-confidence: wsl.exe launched by unusual parents. wsl.exe executing commands via wsl -e or wsl -- that perform system reconnaissance or file access. Monitor for wsl.exe in environments where WSL is not expected or approved. Sysmon within WSL (if deployed) can provide visibility into Linux-side activity.

False positive notes

Extremely common in developer environments. Docker Desktop is a heavy WSL user. VS Code Remote-WSL launches wsl.exe frequently. Self-spawning is normal for WSL internals.

MITRE ATT&CK techniques

Related Processes

com.docker.backend.exewslhost.exe

Ask Rocky about wsl.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for wsl.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.