New Capture Session Launched Via DXCap.EXE

 Original Source: [Sigma source]
Title: New Capture Session Launched Via DXCap.EXE
Status: test
Description:Detects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/
  -https://twitter.com/harr0ey/status/992008180904419328
Author: Beyu Denis, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-10-26
modified:2022-06-09
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\DXCap.exe' OriginalFileName:'DXCap.exe'   selection_cli:
    CommandLine|contains: ' -c '
  condition:all of selection*
Falsepositives:
  -Legitimate execution of dxcap.exe by legitimate user
Level: medium