Skip to content

Hide Navigation Hide TOC

Indirect Command Execution From Script File Via Bash.EXE (2d22a514-e024-4428-9dba-41505bd63a5b)

Detects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect Command Execution From Script File Via Bash.EXE (2d22a514-e024-4428-9dba-41505bd63a5b) Sigma-Rules Indirect Command Execution - T1202 (3b0e52ce-517a-4614-a523-1bd5deef6c5e) Attack Pattern 1