Defender: Review Linux Memory Scan and WSLc

Microsoft updated the “What’s new” page for Microsoft Defender for Endpoint in early September 2026 with two preview notes that matter especially to smaller IT teams running Linux servers or developer endpoints with WSL. Microsoft now lists Memory Scan for Linux and plug-in support for WSL containers. Neither item calls for a rushed rollout, but both are a useful reason to review Defender coverage in Microsoft Defender.

What Microsoft lists for September 2026

On Microsoft Learn, Microsoft lists two Defender for Endpoint capabilities under September 2026 in preview. Memory Scan for Linux is described as inspecting process memory for known malicious behaviours and memory-resident threats. WSL container support extends the Defender for Endpoint plug-in for Windows Subsystem for Linux to WSLc workloads.

  • Memory Scan is documented by Microsoft as a preview feature for Defender for Endpoint on Linux.
  • The capability is available from Defender version 101.26071.0005 in the Insiders-slow channel.
  • WSLc support is also in Public Preview and requires a preview version of the WSL plug-in.
  • The WSL plug-in requires Defender for Endpoint Plan 2 and an onboarded Windows device.

Which dates and versions apply

The Microsoft Learn page “New features in Microsoft Defender for Endpoint” was last updated on 3 September 2026 and places both capabilities in the September 2026 section. It does not state a separate publication day for the features themselves. Internal planning should therefore refer to “September 2026″ and to the documented version requirements, not to a precise launch date that Microsoft does not provide.

For Linux, the decisive requirement is the Defender version: Memory Scan is documented from 101.26071.0005 in the Insiders-slow channel. For WSLc, Microsoft states WSL version 2.9.5 or later and a WSLc-compatible preview version of the Defender plug-in. The regular WSL 2 plug-in is described with installer Defenderplugin-x64-1.26.813.1.msi, while the WSLc preview is obtained through a registration form.

Why Memory Scan can matter on Linux

Microsoft describes Memory Scan as an extra layer of protection against attacks that live in process memory and leave little or no footprint on disk. In small and midsize companies, Linux servers often run business applications, web workloads, infrastructure components, or build services. In those environments, file-based scanning alone may not see the point where an attacker starts tooling directly in memory or injects code into a running process.

Microsoft also explains that the outcome depends on the wider configuration: with Behavior Monitoring enabled and Antivirus Enforcement Level set to Realtime, the feature contributes protection; with Audit it provides detection without remediation; with Passive or On-demand it leaves EDR visibility without AV scanning. That distinction matters during pilots because productive Linux systems can be sensitive to added inspection. Microsoft explicitly notes that advanced scan options might affect performance and recommends default values unless Microsoft Support advises otherwise.

What WSL containers change in coverage

Many developer endpoints use WSL 2 to run Linux tooling directly on Windows. Microsoft describes the Defender for Endpoint WSL plug-in as a way to make WSL instances visible in the Defender portal. With the Public Preview for WSL containers, this visibility extends to WSLc workloads. For companies, that means Linux activity on Windows endpoints does not have to remain outside endpoint visibility.

The Learn documentation also states clear limits. The plug-in provides visibility into events from WSL, while other features such as antimalware, threat and vulnerability management, and response commands are not available for the WSL logical device. Detection and alerting can also vary between Linux distributions. For a Microsoft Security Assessment, the relevant question is therefore not just whether the plug-in installs, but which developer devices and workloads actually benefit from the preview.

Concrete next steps

  • Inventory Linux servers and Windows endpoints that run WSL 2 or WSL containers.
  • Compare Defender version, update channel, WSL version, and plug-in version with Microsoft’s prerequisites.
  • Pilot Memory Scan on a small set of representative Linux systems and monitor performance, alerts, and operational impact.
  • For WSL, use Microsoft’s healthcheck tool and verify that instances appear in the Defender portal.
  • Document exclusions, unsupported devices, and preview dependencies before any broader rollout.

Official Microsoft sources

Whether these preview features fit your environment and how to test them without unnecessary operational risk is something we can review in a Defender check – get in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment