Title:New Capture Session Launched Via DXCap.EXE Status:test Description:Detects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
References: -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/ -https://twitter.com/harr0ey/status/992008180904419328 Author: Beyu Denis, oscd.community, Nasreddine Bencherchali (Nextron Systems) Date: 2019-10-26 modified:2022-06-09 Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection: selection_img: Image|endswith:'\DXCap.exe'OriginalFileName:'DXCap.exe'selection_cli: CommandLine|contains:
' -c ' condition:all of selection* Falsepositives:
-Legitimate execution of dxcap.exe by legitimate user Level:medium