heroui logo

Uncommon Child Process Spawned From XBootMgrSleep.EXE

Sigma Rules

View Source
Summary
Detects an uncommon child process spawned from XBootMgrSleep.exe. Specifically, it flags process creation events where the parent image ends with \xbootmgrsleep.exe but the spawned process is not the expected XBootMgr.exe (path: C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\xbootmgr.exe). XBootMgrSleep.exe is a legitimate, signed Windows Performance Toolkit binary that can delay execution and launch an arbitrary executable. This rule uses a negative filter to permit the expected behavior (launching xbootmgr.exe) while flagging deviations where any other executable is spawned by XBootMgrSleep.exe. Such deviations can indicate abuse for delayed execution of arbitrary payloads. The rule is marked experimental and targets process creation events on Windows endpoints. False positives include legitimate Windows Performance Toolkit automation that uses XBootMgrSleep.exe to start other applications. Follow-up should consider digital signatures, user/parentage context, and in-depth process inspection when triggered.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
Created: 2026-09-27