wsl.exe

by Microsoft
Operating Systemmedium risk

Summary

Windows Subsystem for Linux (wsl.exe) launches and manages Linux distributions running on Windows. It provides the interface between Windows and the WSL2 virtual machine, allowing users to run Linux commands and applications.

wsl.exe is the 95th most commonly executed Windows program in EchoTrail's dataset, observed 261,110 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by wsl.exe.

95th
most commonly executed Windows program
261,110
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3250.03%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.3.0_x64__8wekyb3d8bbwe25.79%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.3.0_x64__8wekyb3d8bbwe17.61%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.0.0_x64__8wekyb3d8bbwe5.86%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.6.0_x64__8wekyb3d8bbwe0.39%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.5.0_x64__8wekyb3d8bbwe0.13%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.0.0_x64__8wekyb3d8bbwe0.1%
  • C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_0.70.4.0_x64__8wekyb3d8bbwe0.09%

Top Hashes (SHA256)

  • 90711b2c90306034f4f9a2fb7cddcf1d514e64c435cbc1fc81003059c19a343d49.97%
  • 6b36f68114e03e647641b65282d9c14c57115fdc5bfaebf97d502c7c99848ed425.79%
  • 56187b1998193ddb24eed8c88f0fcc0ac03bf92865affa85667a2382626f625717.61%
  • 876d4aeb17118a5a55465da1501f8c7a1af5a6ac14712b5805205bfb317fac895.86%
  • 7e1cb7959028b4d16fc82af0b55f4bc759739bd6e4f43f29103d67cc8dd657780.39%
  • 36e9d37ba8b69207a794e8b6fbed30f368789ad82a96f67f87c72f8605a085000.13%
  • c814c244b636ab1a7c65ee12146b84241fc9485981a1fb09c3a1b449fe91ad480.1%
  • 67331b0dccbe70ced849c958a3c768b992a3ca8243328a858bbc7820e1a9357b0.09%
  • 9e724c5a8000dd595d6d278fbe85b6f043f35cb1acc77d71f5849975064d293f0.03%
  • f0556e52dd41e2a16cf273600492abe4a3d196634b9bd1426c8e6706b418d8620.02%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does wsl.exe normally do?

Located in C:\Windows\System32 or Windows Apps directory. Commonly launched by itself (recursive for WSL internals), Docker Desktop (com.docker.backend.exe), and VS Code (Code.exe). Spawns wslhost.exe and conhost.exe.

When is wsl.exe suspicious?

Launched by unexpected parents (Office applications, script interpreters). Used to execute commands that bypass Windows-native security controls (WSL Linux binaries are not subject to AppLocker or WDAC). Data exfiltration through WSL file system access (WSL can access the full Windows file system via /mnt/c/).

How do attackers abuse wsl.exe?

Security control bypass: WSL provides a Linux environment that may bypass Windows security tooling (AppLocker, AMSI, Defender). Attackers can download and execute Linux-native tools from within WSL. Cross-platform attack: WSL can access the full Windows file system, enabling data theft or modification from within the Linux environment without triggering Windows file monitoring. Defense evasion: Linux binaries executed within WSL may not be visible to Windows EDR tools.

Detection guidance

Medium-confidence: wsl.exe launched by unusual parents. wsl.exe executing commands via wsl -e or wsl -- that perform system reconnaissance or file access. Monitor for wsl.exe in environments where WSL is not expected or approved. Sysmon within WSL (if deployed) can provide visibility into Linux-side activity.

False positive notes

Extremely common in developer environments. Docker Desktop is a heavy WSL user. VS Code Remote-WSL launches wsl.exe frequently. Self-spawning is normal for WSL internals.

MITRE ATT&CK techniques

Related Processes

com.docker.backend.exewslhost.exe

Ask Rocky about wsl.exe

Rocky answers questions about wsl.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.