wsl.exe
Summary
Windows Subsystem for Linux (wsl.exe) launches and manages Linux distributions running on Windows. It provides the interface between Windows and the WSL2 virtual machine, allowing users to run Linux commands and applications.
wsl.exe is the 95th most commonly executed Windows program in EchoTrail's dataset, observed 261,110 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by wsl.exe.
Behavior
Top Paths
- C:\Windows\System3250.03%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.3.0_x64__8wekyb3d8bbwe25.79%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.3.0_x64__8wekyb3d8bbwe17.61%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.0.0.0_x64__8wekyb3d8bbwe5.86%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.1.6.0_x64__8wekyb3d8bbwe0.39%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.5.0_x64__8wekyb3d8bbwe0.13%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_1.2.0.0_x64__8wekyb3d8bbwe0.1%
- C:\Program Files\WindowsApps\MicrosoftCorporationII.WindowsSubsystemForLinux_0.70.4.0_x64__8wekyb3d8bbwe0.09%
Top Hashes (SHA256)
- 90711b2c90306034f4f9a2fb7cddcf1d514e64c435cbc1fc81003059c19a343d49.97%
- 6b36f68114e03e647641b65282d9c14c57115fdc5bfaebf97d502c7c99848ed425.79%
- 56187b1998193ddb24eed8c88f0fcc0ac03bf92865affa85667a2382626f625717.61%
- 876d4aeb17118a5a55465da1501f8c7a1af5a6ac14712b5805205bfb317fac895.86%
- 7e1cb7959028b4d16fc82af0b55f4bc759739bd6e4f43f29103d67cc8dd657780.39%
- 36e9d37ba8b69207a794e8b6fbed30f368789ad82a96f67f87c72f8605a085000.13%
- c814c244b636ab1a7c65ee12146b84241fc9485981a1fb09c3a1b449fe91ad480.1%
- 67331b0dccbe70ced849c958a3c768b992a3ca8243328a858bbc7820e1a9357b0.09%
- 9e724c5a8000dd595d6d278fbe85b6f043f35cb1acc77d71f5849975064d293f0.03%
- f0556e52dd41e2a16cf273600492abe4a3d196634b9bd1426c8e6706b418d8620.02%
Process Ancestry
Top Grandparents
- sihost.exe100%
Top Parents
- wsl.exe49.97%
- Code.exe0.39%
- WindowsTerminal.exe0.16%
- cmd.exe0.12%
- Docker Desktop.exe0.04%
- pwsh.exe<0.01%
- powershell.exe<0.01%
- explorer.exe<0.01%
Top Children
- wsl.exe49.8%
- wslhost.exe49.58%
- conhost.exe0.43%
- DismHost.exe<0.01%
- msiexec.exe<0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does wsl.exe normally do?
Located in C:\Windows\System32 or Windows Apps directory. Commonly launched by itself (recursive for WSL internals), Docker Desktop (com.docker.backend.exe), and VS Code (Code.exe). Spawns wslhost.exe and conhost.exe.
When is wsl.exe suspicious?
Launched by unexpected parents (Office applications, script interpreters). Used to execute commands that bypass Windows-native security controls (WSL Linux binaries are not subject to AppLocker or WDAC). Data exfiltration through WSL file system access (WSL can access the full Windows file system via /mnt/c/).
How do attackers abuse wsl.exe?
Security control bypass: WSL provides a Linux environment that may bypass Windows security tooling (AppLocker, AMSI, Defender). Attackers can download and execute Linux-native tools from within WSL. Cross-platform attack: WSL can access the full Windows file system, enabling data theft or modification from within the Linux environment without triggering Windows file monitoring. Defense evasion: Linux binaries executed within WSL may not be visible to Windows EDR tools.
Detection guidance
Medium-confidence: wsl.exe launched by unusual parents. wsl.exe executing commands via wsl -e or wsl -- that perform system reconnaissance or file access. Monitor for wsl.exe in environments where WSL is not expected or approved. Sysmon within WSL (if deployed) can provide visibility into Linux-side activity.
False positive notes
Extremely common in developer environments. Docker Desktop is a heavy WSL user. VS Code Remote-WSL launches wsl.exe frequently. Self-spawning is normal for WSL internals.
Related Processes
Ask Rocky about wsl.exe
Rocky answers questions about wsl.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.