WSL1 Ignoring Ransomware Protection on Win10 (20H2)?

Subscribers:
757
Published on ● Video Link: https://www.youtube.com/watch?v=jLFWS5xUC8w



Duration: 1:17
40 views
0


Demonstration that Ransomware Protection in Win10 (20H2) will prevent certain WSL1 commands such as "bash" from writing to a file in a protected folder however it does not prevent the "mv" command from moving the file. Both actions trigger events stating that the operation has been blocked however the "mv" command is still able to successfully move the file.

Some supporting files showing screenshots of the block events in the Windows Security area and exports of the events from the Windows Defender Event Log: https://pileofgarbage.net/weirdsl/

Music: π—£π—Ώπ—²π˜π—²π—»π—±π—²π—Ώ by π˜Šπ˜­π˜’π˜΄π˜©π˜›π˜°π˜―π˜¦, from the π——π—Άπ˜ƒπ—²π—Ώπ—΄π—²π—»π—°π—² π—œπ—œ π—Ÿπ—£ (EATBRAINLP009) compilation released on 𝘌𝘒𝘡𝘣𝘳𝘒π˜ͺ𝘯. https://youtu.be/J0wll3H9Gc8


π—˜π—±π—Άπ˜: further investigation has revealed the issue only affects WSL1 and not WSL2 which works differently.