{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/dism/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows Subsystem for Linux"],"_cs_severities":["medium"],"_cs_tags":["defense-evasion","wsl","dism"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Windows Subsystem for Linux (WSL) allows users to run Linux distributions and command-line tools natively on Windows. Adversaries often abuse this feature to evade security protections, as Linux-based tooling and bash environments may not be monitored by security tools configured strictly for Windows binaries. This technique involves using the built-in Deployment Image Servicing and Management (DISM) utility to programmatically enable the WSL feature on a compromised host. By transitioning the environment to include Linux capabilities, attackers gain a platform to execute malicious scripts, deploy Linux-based malware, or perform post-exploitation tasks while minimizing their footprint on the Windows host's primary security stack. Monitoring for unauthorized use of DISM to modify Windows features is a critical component of endpoint security.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the Windows host through phishing or exploit.\u003c/li\u003e\n\u003cli\u003eAttacker identifies that WSL is not enabled, limiting their ability to execute custom Linux payloads.\u003c/li\u003e\n\u003cli\u003eAttacker executes \u003ccode\u003eDism.exe\u003c/code\u003e with administrative privileges.\u003c/li\u003e\n\u003cli\u003eAttacker supplies the \u003ccode\u003e/Enable-Feature\u003c/code\u003e argument targeting \u003ccode\u003eMicrosoft-Windows-Subsystem-Linux\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe OS enables the subsystem, potentially requiring a system reboot or further configuration.\u003c/li\u003e\n\u003cli\u003eAttacker downloads or executes Linux-native payloads or shells (e.g., bash).\u003c/li\u003e\n\u003cli\u003eAttacker performs malicious activity, such as exfiltration or lateral movement, using the Linux environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to operate within a Linux environment on a Windows host, effectively bypassing security controls that lack visibility into Linux-native execution or shell activity. This can lead to persistent access, enhanced capability to deploy complex cross-platform malware, and increased difficulty for incident responders to perform forensic analysis, as malicious activity may be logged in Linux-specific locations rather than standard Windows event logs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of the \u003ccode\u003eDism.exe\u003c/code\u003e utility and establish a baseline for authorized feature changes in the environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect \u003ccode\u003eDism.exe\u003c/code\u003e invocations that enable WSL.\u003c/li\u003e\n\u003cli\u003eReview administrative activity logs for \u003ccode\u003eDism.exe\u003c/code\u003e execution across all endpoints.\u003c/li\u003e\n\u003cli\u003eEstablish a process for identifying and authorizing WSL usage within the enterprise.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon process-creation logging (Event ID 1) to ensure the detection of process command-line arguments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T16:41:26Z","date_published":"2026-10-07T16:41:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wsl-dism-evasion/","summary":"Adversaries may attempt to enable the Windows Subsystem for Linux (WSL) using the legitimate DISM utility to facilitate the execution of Linux-based tools and bypass Windows-specific security controls.","title":"Defense Evasion via WSL Enablement using DISM","url":"https://feed.craftedsignal.io/briefs/2026-10-wsl-dism-evasion/"}],"language":"en","title":"CraftedSignal Threat Feed - Dism","version":"https://jsonfeed.org/version/1.1"}