In brief

A talk with a negative result, and that is its main value: the Linux subsystem in Windows has practically no forensic artifacts of its own — no ETW providers, no text logs, no databases, only indirect traces in the registry and a couple of logs. What WSL2 does have is three properties that attackers make use of: Windows executables can be launched from a Linux distribution, the host file system is mounted inside it, and the network stack is isolated — that is, Sysmon and EDR on the host do not see the network activity. Then come three public cases (an ELF ransomware at Qilin affiliates, a stealer through npm typosquatting), the ways of persistence and of delivering a custom distribution, and the conclusion: there is no separate "WSL forensics", what is left is Windows forensics plus Linux forensics inside ext4.vhdx. Separately the speaker takes apart how a false list of groups appeared in publications, and calls it neural slop.

Key points

Tools, artifacts, technologies

There is no legal or procedural content — the talk is purely technical, addressed to DFIR specialists and to SOCs. There is one organizational recommendation and it comes in an answer to a question: restrict the use of WSL for users and monitor the enabling of the components, since only a handful of people need the subsystem — "hardly some accountant or lawyer".

Questions from the audience

The speaker's position

A rare talk built on a negative result and stating so outright: there are no artifacts, there will be no magic log, work with the standard means of the two operating systems. The strongest episode is the analysis of how an unreliable claim about groups spread through publications, and the refusal to repeat it. Where there is no data, the speaker says he does not have "that kind of analytics or statistics" instead of giving estimates. The other side: the attacking part is worked through noticeably better than the defensive one, and he cannot offer any specific means of detection — the limit of the recommendations comes down to "restrict and monitor the enabling of the components".

Quotes