LOLBAS/yml/OtherMSBinaries/Dxcap.yml

18 lines
437 B
YAML

---
Name: Dxcap.exe
Description: Execute
Author: ''
Created: '2018-05-25'
Categories: []
Commands:
- Command: Dxcap.exe -c C:\Windows\System32\notepad.exe
Description: Launch notepad as a subprocess of Dxcap.exe
Full Path:
- c:\Windows\System32\dxcap.exe
- c:\Windows\SysWOW64\dxcap.exe
Code Sample: []
Detection: []
Resources:
- https://twitter.com/harr0ey/status/992008180904419328
Notes: Thanks to Matt harr0ey - @harr0ey