Indirect Inline Command Execution Via Bash.EXE

 Original Source: [Sigma source]
Title: Indirect Inline Command Execution Via Bash.EXE
Status: test
Description:Detects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Bash/
Author: frack113
Date: 2021-11-24
modified:2023-08-15
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - ':\Windows\System32\bash.exe'
      - ':\Windows\SysWOW64\bash.exe'
OriginalFileName:'Bash.exe'   selection_cli:
    CommandLine|contains: ' -c '
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium