Bash (cef3a09e-22ca-43dc-ad4a-95741a3b85ff)
This object contains information sourced from the Living Off The Land Binaries, Scripts and Libraries (LOLBAS) project, which is licensed under GNU General Public License v3.0.
Description: File used by Windows subsystem for Linux
Author: Oddvar Moe
Paths: * C:\Windows\System32\bash.exe * C:\Windows\SysWOW64\bash.exe
Detection: * BlockRule: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules * Sigma: proc_creation_win_lolbin_bash.yml * IOC: Child process from bash.exe[Bash.exe - LOLBAS Project]