diff --git a/rules/windows/process_creation/win_susp_dxcap.yml b/rules/windows/process_creation/win_susp_dxcap.yml index 3fb6272ad..afd02da5c 100644 --- a/rules/windows/process_creation/win_susp_dxcap.yml +++ b/rules/windows/process_creation/win_susp_dxcap.yml @@ -1,6 +1,6 @@ title: Bypassing Application Whitelisting by using dxcap.exe status: experimental -description: Local execution of a process as a subprocess of Dxcap.exe +description: Local execution of a process as a subprocess of Dxcap.exe references: - https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Dxcap.yml - https://twitter.com/harr0ey/status/992008180904419328