Skip to content

Hide Navigation Hide TOC

Indirect Inline Command Execution Via Bash.EXE (5edc2273-c26f-406c-83f3-f4d948e740dd)

Detects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect Command Execution - T1202 (3b0e52ce-517a-4614-a523-1bd5deef6c5e) Attack Pattern Indirect Inline Command Execution Via Bash.EXE (5edc2273-c26f-406c-83f3-f4d948e740dd) Sigma-Rules 1