~/Privilege Escalation/Windows/Binaries# cat Dxcap.exe.md

DirectX diagnostics/debugger included with Visual Studio.

Paths:

C:\Windows\System32\dxcap.exe
C:\Windows\SysWOW64\dxcap.exe

Detection:

Execute

Launch notepad as a subprocess of Dxcap.exe

Dxcap.exe -c C:\Windows\System32\notepad.exe