Uncommon Child Process Spawned by XBootMgrSleep.exe (Windows Performance Toolkit)

Alerts when XBootMgrSleep.exe launches an unexpected child process on Windows, indicating potential delayed execution abuse.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Diablo Research (SigmaHQ), DRL 1.1
Published
2026-09-27
Updated
2026-10-03
title: Uncommon Child Process Spawned by XBootMgrSleep.exe (Windows Performance Toolkit)
id: 64befbe4-2584-4908-85eb-6148848035aa
status: experimental
description: This rule flags process creation events where XBootMgrSleep.exe spawns a child process other than the expected XBootMgr.exe executable. Attackers can abuse signed Windows Performance Toolkit binaries to delay execution and launch arbitrary code indirectly. The detection relies on process creation telemetry, specifically the parent process image path ending with \xbootmgrsleep.exe and the child process image path.
references:
  - https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/
  - https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_xbootmgrsleep_uncommon_child_process.yml
author: Diablo Research, Huntrule Team
date: 2026-09-27
tags:
  - attack.stealth
  - attack.t1202
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith: \xbootmgrsleep.exe
  filter_main_xbootmgr:
    Image: C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\xbootmgr.exe
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Custom Windows Performance Toolkit automation that intentionally launches another executable through XBootMgrSleep.exe
level: medium
license: DRL-1.1
related:
  - id: 74697c29-1b30-4e1f-a517-33574061821d
    type: derived