Potential WSL VM Instance Started

Rule Info

Name
Potential WSL VM Instance Started
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects potential WSL VM instance start based on their VM names being UUIDv4 formatted.
Date
2024-01-10 00:00:00
Modified
None
Id
6d5f46a9-f9aa-4ab2-9679-15939415fe4d
Tags
attack.defense-evasion
Type
Nextron Sigma feed only (private)

Rule History