{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
        "slug": "dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/"
        },
        "title": "Route WSL findings through the host without assuming full Linux response features",
        "summary": "Does the Defender WSL logical device provide the same protection and response functions as a full Linux endpoint?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:11+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 253,
        "potentially_affected": "Supported Windows 11 hosts using the Defender for Endpoint plug-in for traditional WSL 2 distributions.",
        "dse_recommendation": "Record the WSL-to-Windows host mapping and test the intended investigation handoff rather than assuming response parity.",
        "primary_source": {
            "name": "Microsoft Defender for Endpoint plug-in for Windows Subsystem for Linux (WSL) - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The Defender for Endpoint WSL plug-in exposes subsystem events, but antimalware, vulnerability management and response commands are unavailable on the WSL logical device. The portal represents it as Linux with a link to its Windows host. DeviceInfo&#8217;s HostDeviceId supports that mapping in hunting queries. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The plug-in requires an onboarded Windows host and an active distribution with WSL 2.0.7.0 or later. ARM64, multi-session Windows and custom-kernel configurations are unsupported. Short-lived instances can disappear before onboarding becomes visible; Microsoft allows up to 30 minutes for WSL 2 onboarding. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review supported Windows 11 hosts using the Defender for Endpoint plug-in for traditional WSL 2 distributions. WSL container support is a separate public preview and is outside this brief.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends including both logical-device and Windows-host identifiers in a WSL investigation record. Decide in advance where an analyst should hand off a response action that the subsystem device cannot perform. Keep event visibility separate from antivirus or vulnerability-assessment coverage. Review short-lived development workloads explicitly instead of counting the absence of a portal object as evidence that WSL was never used.</p>\n<h2>Verification</h2>\n<p>Use an approved representative distribution long enough to complete initialization, inspect plug-in health, and correlate a harmless process event with the correct Windows host. Confirm the analyst can follow the hosting relationship without confusing two similarly named objects. Record unsupported configurations and any response step requiring the host team&#8217;s authority. Do not treat a populated timeline as proof that unavailable protection features are active.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Defender plug-in for WSL</a>.</p>",
        "content_text": "Source facts\nThe Defender for Endpoint WSL plug-in exposes subsystem events, but antimalware, vulnerability management and response commands are unavailable on the WSL logical device. The portal represents it as Linux with a link to its Windows host. DeviceInfo’s HostDeviceId supports that mapping in hunting queries. Microsoft Learn.\nThe plug-in requires an onboarded Windows host and an active distribution with WSL 2.0.7.0 or later. ARM64, multi-session Windows and custom-kernel configurations are unsupported. Short-lived instances can disappear before onboarding becomes visible; Microsoft allows up to 30 minutes for WSL 2 onboarding. Microsoft Learn.\nApplicability\nReview supported Windows 11 hosts using the Defender for Endpoint plug-in for traditional WSL 2 distributions. WSL container support is a separate public preview and is outside this brief.\nDSE recommendation\nDSE recommends including both logical-device and Windows-host identifiers in a WSL investigation record. Decide in advance where an analyst should hand off a response action that the subsystem device cannot perform. Keep event visibility separate from antivirus or vulnerability-assessment coverage. Review short-lived development workloads explicitly instead of counting the absence of a portal object as evidence that WSL was never used.\nVerification\nUse an approved representative distribution long enough to complete initialization, inspect plug-in health, and correlate a harmless process event with the correct Windows host. Confirm the analyst can follow the hosting relationship without confusing two similarly named objects. Record unsupported configurations and any response step requiring the host team’s authority. Do not treat a populated timeline as proof that unavailable protection features are active.\nOfficial references\nMicrosoft Learn: Defender plug-in for WSL.",
        "content_markdown": "## Source facts\n\nThe Defender for Endpoint WSL plug-in exposes subsystem events, but antimalware, vulnerability management and response commands are unavailable on the WSL logical device. The portal represents it as Linux with a link to its Windows host. DeviceInfo’s HostDeviceId supports that mapping in hunting queries. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl).\n\nThe plug-in requires an onboarded Windows host and an active distribution with WSL 2.0.7.0 or later. ARM64, multi-session Windows and custom-kernel configurations are unsupported. Short-lived instances can disappear before onboarding becomes visible; Microsoft allows up to 30 minutes for WSL 2 onboarding. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl).\n\n## Applicability\n\nReview supported Windows 11 hosts using the Defender for Endpoint plug-in for traditional WSL 2 distributions. WSL container support is a separate public preview and is outside this brief.\n\n## DSE recommendation\n\nDSE recommends including both logical-device and Windows-host identifiers in a WSL investigation record. Decide in advance where an analyst should hand off a response action that the subsystem device cannot perform. Keep event visibility separate from antivirus or vulnerability-assessment coverage. Review short-lived development workloads explicitly instead of counting the absence of a portal object as evidence that WSL was never used.\n\n## Verification\n\nUse an approved representative distribution long enough to complete initialization, inspect plug-in health, and correlate a harmless process event with the correct Windows host. Confirm the analyst can follow the hosting relationship without confusing two similarly named objects. Record unsupported configurations and any response step requiring the host team’s authority. Do not treat a populated timeline as proof that unavailable protection features are active.\n\n## Official references\n\n[Microsoft Learn: Defender plug-in for WSL](https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Route WSL findings through the host without assuming full Linux response features",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/",
                "headline": "Route WSL findings through the host without assuming full Linux response features",
                "description": "Does the Defender WSL logical device provide the same protection and response functions as a full Linux endpoint?",
                "abstract": "Does the Defender WSL logical device provide the same protection and response functions as a full Linux endpoint?",
                "articleBody": "Source facts\nThe Defender for Endpoint WSL plug-in exposes subsystem events, but antimalware, vulnerability management and response commands are unavailable on the WSL logical device. The portal represents it as Linux with a link to its Windows host. DeviceInfo’s HostDeviceId supports that mapping in hunting queries. Microsoft Learn.\nThe plug-in requires an onboarded Windows host and an active distribution with WSL 2.0.7.0 or later. ARM64, multi-session Windows and custom-kernel configurations are unsupported. Short-lived instances can disappear before onboarding becomes visible; Microsoft allows up to 30 minutes for WSL 2 onboarding. Microsoft Learn.\nApplicability\nReview supported Windows 11 hosts using the Defender for Endpoint plug-in for traditional WSL 2 distributions. WSL container support is a separate public preview and is outside this brief.\nDSE recommendation\nDSE recommends including both logical-device and Windows-host identifiers in a WSL investigation record. Decide in advance where an analyst should hand off a response action that the subsystem device cannot perform. Keep event visibility separate from antivirus or vulnerability-assessment coverage. Review short-lived development workloads explicitly instead of counting the absence of a portal object as evidence that WSL was never used.\nVerification\nUse an approved representative distribution long enough to complete initialization, inspect plug-in health, and correlate a harmless process event with the correct Windows host. Confirm the analyst can follow the hosting relationship without confusing two similarly named objects. Record unsupported configurations and any response step requiring the host team’s authority. Do not treat a populated timeline as proof that unavailable protection features are active.\nOfficial references\nMicrosoft Learn: Defender plug-in for WSL.",
                "datePublished": "2026-09-10T00:22:11+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-585-route-wsl-findings-through-the-host-without-assuming-full-linux-response-features/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Route WSL findings through the host without assuming full Linux response features"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 253,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Defender for Endpoint plug-in for Windows Subsystem for Linux (WSL) - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/mde-plugin-wsl"
                }
            }
        ]
    }
}