ASR Rule “Block use of copied or impersonated system tools” blocks on WSL
Our team was encountering difficulties with using Linux VMs within WSL after this rule was deployed to the fleet. Is this expected behavior, given wsl.exe is a Microsoft system tool? If so, I recommend documentation be updated _somewhere_ to indicate the need for administrators to exempt this interaction somehow. Otherwise, the ASR rule may need to be updated to interact properly with WSL.
Our team was encountering difficulties with using Linux VMs within WSL after this rule was deployed to the fleet. Is this expected behavior, given wsl.exe is a Microsoft system tool? If so, I recommend documentation be updated _somewhere_ to indicate the need for administrators to exempt this interaction somehow. Otherwise, the ASR rule may need to be updated to interact properly with WSL. Read More