From 7b44bd9ac62596bbbd0317ad0412eafc046594d7 Mon Sep 17 00:00:00 2001 From: Avihay Eldad <46644022+avihayeldad@users.noreply.github.com> Date: Mon, 29 Sep 2025 23:47:41 +0300 Subject: [PATCH] Create Pixtool.yml (#463) Co-authored-by: Wietze --- yml/OtherMSBinaries/Pixtool.yml | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 yml/OtherMSBinaries/Pixtool.yml diff --git a/yml/OtherMSBinaries/Pixtool.yml b/yml/OtherMSBinaries/Pixtool.yml new file mode 100644 index 0000000..5860c66 --- /dev/null +++ b/yml/OtherMSBinaries/Pixtool.yml @@ -0,0 +1,23 @@ +--- +Name: Pixtool.exe +Description: Command line utility for taking and analyzing PIX GPU captures. +Author: Avihay Eldad +Created: 2025-09-21 +Commands: + - Command: pixtool.exe launch {PATH_ABSOLUTE:.exe} + Description: Launches an executable via PIX command-line utility. + Usecase: Executes an executable under a trusted, Microsoft signed binary. + Category: Execute + Privileges: User + MitreID: T1127 + OperatingSystem: Windows + Tags: + - Execute: EXE +Full_Path: + - Path: C:\Program Files\Microsoft PIX\pixtool.exe + - Path: C:\Program Files (x86)\Microsoft PIX\pixtool.exe +Resources: + - Link: https://devblogs.microsoft.com/pix/pixtool/ +Acknowledgement: + - Person: Avihay Eldad + Handle: '@AvihayEldad'