<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dism - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/dism/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:41:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/dism/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Defense Evasion via WSL Enablement using DISM</title><link>https://feed.craftedsignal.io/briefs/2026-10-wsl-dism-evasion/</link><pubDate>Wed, 07 Oct 2026 16:41:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wsl-dism-evasion/</guid><description>Adversaries may attempt to enable the Windows Subsystem for Linux (WSL) using the legitimate DISM utility to facilitate the execution of Linux-based tools and bypass Windows-specific security controls.</description><content:encoded><![CDATA[<p>The Windows Subsystem for Linux (WSL) allows users to run Linux distributions and command-line tools natively on Windows. Adversaries often abuse this feature to evade security protections, as Linux-based tooling and bash environments may not be monitored by security tools configured strictly for Windows binaries. This technique involves using the built-in Deployment Image Servicing and Management (DISM) utility to programmatically enable the WSL feature on a compromised host. By transitioning the environment to include Linux capabilities, attackers gain a platform to execute malicious scripts, deploy Linux-based malware, or perform post-exploitation tasks while minimizing their footprint on the Windows host's primary security stack. Monitoring for unauthorized use of DISM to modify Windows features is a critical component of endpoint security.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains initial access to the Windows host through phishing or exploit.</li>
<li>Attacker identifies that WSL is not enabled, limiting their ability to execute custom Linux payloads.</li>
<li>Attacker executes <code>Dism.exe</code> with administrative privileges.</li>
<li>Attacker supplies the <code>/Enable-Feature</code> argument targeting <code>Microsoft-Windows-Subsystem-Linux</code>.</li>
<li>The OS enables the subsystem, potentially requiring a system reboot or further configuration.</li>
<li>Attacker downloads or executes Linux-native payloads or shells (e.g., bash).</li>
<li>Attacker performs malicious activity, such as exfiltration or lateral movement, using the Linux environment.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to operate within a Linux environment on a Windows host, effectively bypassing security controls that lack visibility into Linux-native execution or shell activity. This can lead to persistent access, enhanced capability to deploy complex cross-platform malware, and increased difficulty for incident responders to perform forensic analysis, as malicious activity may be logged in Linux-specific locations rather than standard Windows event logs.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring of the <code>Dism.exe</code> utility and establish a baseline for authorized feature changes in the environment.</p>
<ul>
<li>Deploy the provided Sigma rule to detect <code>Dism.exe</code> invocations that enable WSL.</li>
<li>Review administrative activity logs for <code>Dism.exe</code> execution across all endpoints.</li>
<li>Establish a process for identifying and authorizing WSL usage within the enterprise.</li>
<li>Enable Sysmon process-creation logging (Event ID 1) to ensure the detection of process command-line arguments.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>defense-evasion</category><category>wsl</category><category>dism</category></item></channel></rss>