Uncommon Child Process Spawned From XBootMgrSleep.EXE
Detects a process other than XBootMgr.exe spawned by XBootMgrSleep.exe. XBootMgrSleep.exe is a Microsoft-signed Windows Performance Toolkit binary that can execute an arbitrary executable after a delay.
Detection logic
Detection requirements
- Platform
- Windows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source product
- windows
- Log source category
- process_creation
Known benign triggers
- Custom Windows Performance Toolkit automation that intentionally launches another executable through XBootMgrSleep.exe
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference | Only this detection cites it |
| lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/ | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- 74697c29-1b30-4e1f-a517-33574061821d
- Tagged by the source as
- attack.stealth
Licence
- Published under
- Detection Rule License 1.1Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 3, 2026
- Version
- 1