WSL as a Blind Spot for Windows Endpoint Data Loss Prevention Controls
I evaluated how Windows Subsystem for Linux (WSL) can be leveraged to circumvent endpoint Data Loss Prevention (DLP) controls. Through laboratory experiments across multiple Windows platforms, I found that a commercial endpoint DLP solution—configured with industry-standard policies—exhibits complete visibility loss when identical data-exfiltration operations are executed from WSL instead of native Windows. Out of 110 test operations spanning file operations, network exfiltration, removable media, and cloud storage channels, WSL-based activities bypassed DLP enforcement 100% of the time (zero alerts, zero logs, zero policy enforcement), whereas equivalent Windows-based operations achieved 100% detection and enforcement across 90 baseline operations. This work introduces the concept of WSL DLP blind spots, provides empirical evidence across six data channels, presents a practical threat model, and proposes concrete risk mitigation strategies for organizations deploying both WSL and endpoint DLP.
Authors
- Sai Naveen Nukala (ORCID: https://orcid.org/0009-0009-7141-1724)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-25
- DOI
- https://doi.org/10.5281/zenodo.22961986
- Primary Topic
- Security and Verification in Computing
- Type
- preprint