Uncommon Child Process Spawned by XBootMgrSleep.exe (Windows Performance Toolkit)
Alerts when XBootMgrSleep.exe launches an unexpected child process on Windows, indicating potential delayed execution abuse.
- Product
- windows
- Category
- process_creation
- Author
- Diablo Research (SigmaHQ), DRL 1.1
- Published
- 2026-09-27
- Updated
- 2026-10-03
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where XBootMgrSleep.exe spawns a child process other than the expected XBootMgr.exe executable. Attackers can abuse signed Windows Performance Toolkit binaries to delay execution and launch arbitrary code indirectly. The detection relies on process creation telemetry, specifically the parent process image path ending with \xbootmgrsleep.exe and the child process image path.
Reporting behind it
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/
- learn.microsoft.comhttps://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_xbootmgrsleep_uncommon_child_process.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Uncommon Child Process Spawned by XBootMgrSleep.exe (Windows Performance Toolkit)
id: 64befbe4-2584-4908-85eb-6148848035aa
status: experimental
description: This rule flags process creation events where XBootMgrSleep.exe spawns a child process other than the expected XBootMgr.exe executable. Attackers can abuse signed Windows Performance Toolkit binaries to delay execution and launch arbitrary code indirectly. The detection relies on process creation telemetry, specifically the parent process image path ending with \xbootmgrsleep.exe and the child process image path.
references:
- https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/
- https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_xbootmgrsleep_uncommon_child_process.yml
author: Diablo Research, Huntrule Team
date: 2026-09-27
tags:
- attack.stealth
- attack.t1202
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: \xbootmgrsleep.exe
filter_main_xbootmgr:
Image: C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\xbootmgr.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Custom Windows Performance Toolkit automation that intentionally launches another executable through XBootMgrSleep.exe
level: medium
license: DRL-1.1
related:
- id: 74697c29-1b30-4e1f-a517-33574061821d
type: derived