GNU Bash
product · product:gnu-bash single-source-national-cert
Defender insights
What each entry about GNU Bash tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (16 across 8 tactics)
16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Vulnerability Scanning
- Initial AccessExternal Remote Services · Drive-by Compromise · Exploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python · Command and Scripting Interpreter: JavaScript
- PersistenceExternal Remote Services
- StealthMasquerading: Rename Legitimate Utilities
- Credential AccessOS Credential Dumping: DCSync · Brute Force: Password Guessing · Brute Force: Password Spraying
- CollectionData Staged: Local Data Staging · Email Collection: Remote Email Collection · Archive Collected Data: Archive via Custom Method
- ExfiltrationAutomated Exfiltration
Reconnaissance TA0043
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Persistence TA0003
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Stealth TA0005
T1036.003Masquerading: Rename Legitimate Utilities×1
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename <code>rundll32.exe</code>). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Credential Access TA0006
T1003.006OS Credential Dumping: DCSync×1
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1110.001Brute Force: Password Guessing×1
Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1110.003Brute Force: Password Spraying×1
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Collection TA0009
T1074.001Data Staged: Local Data Staging×1
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1114.002Email Collection: Remote Email Collection×1
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
T1560.003Archive Collected Data: Archive via Custom Method×1
An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Exfiltration TA0010
T1020Automated Exfiltration×1
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.
Evidence: 2026-10-09/aa26-281a-integrity-tech-microscan-exchange-mail-theft · ATT&CK page ↗
Entries about GNU Bash (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Apache Struts×1
- Apache Struts 2.3.19 to 2.3.28: command injection with Dynamic Method Invocation enabled, exploited per AA26-281A and added to CISA KEV 2026-10-08×1
- FishHub×1
- Flax Typhoon×1
- GitLab×1
- GitLab from 11.9: code injection through image upload handling, listed as exploited in AA26-281A×1
- GNU Bash through 4.3: OS command injection through a crafted environment, listed as exploited in AA26-281A×1
- Integrity Technology Group×1
Where this entity is cited
Source distribution
- cisa.gov1 (17%)
- cwiki.apache.org1 (17%)
- ic3.gov1 (17%)
- justice.gov1 (17%)
- ncsc.gov.uk1 (17%)
- strapi.io1 (17%)
All cited sources (6)
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- cwiki.apache.orgApache Struts (S2-032)https://cwiki.apache.org/confluence/display/WW/S2-032
- ic3.govFBI, CISA, NSA, NCSC UK and partners (joint advisory AA26-281A)https://www.ic3.gov/CSA/2026/261008.pdf
- justice.govU.S. Department of Justicehttps://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
- ncsc.gov.ukNCSC UKhttps://www.ncsc.gov.uk/news/china-linked-actors-called-out-by-uk-and-international-partners-for-targeting-sensitive-data
- strapi.ioStrapihttps://strapi.io/blog/security-disclosure-of-vulnerabilities-cve