{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/windows-performance-toolkit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows Performance Toolkit"],"_cs_severities":["medium"],"_cs_tags":["living-off-the-land","execution","windows-performance-toolkit"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eXBootMgrSleep.exe is a utility distributed as part of the Microsoft Windows Performance Toolkit. Security research identifies this binary as a potential Living-off-the-Land (LotL) vector, as it possesses the inherent capability to execute an arbitrary secondary binary after a specified delay. Because the tool is Microsoft-signed, adversaries may leverage it to execute malicious payloads or secondary stage implants while evading reputation-based detection mechanisms that trust binaries within the Windows Kits directory. Monitoring for unusual child processes spawned by this specific utility is critical for identifying potential persistence or execution staging, as the tool is rarely required in standard end-user or workstation environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this technique allows attackers to maintain execution of unauthorized code under the umbrella of a trusted, digitally signed Microsoft process, potentially bypassing application control policies and environment monitoring that relies solely on process path or signature verification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to detect non-standard child processes initiated by the XBootMgrSleep.exe binary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Sysmon process-creation logging (Event ID 1) to capture the full command line and parent process information required for this detection.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for legitimate usage of the Windows Performance Toolkit in your environment to minimize false positives from authorized diagnostic scripts.\u003c/li\u003e\n\u003cli\u003eInvestigate any alert triggered by this rule to determine if the spawned process is a known administrative utility or an unauthorized artifact.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T12:13:04Z","date_published":"2026-10-02T12:13:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-xbootmgrsleep-spawn/","summary":"Detection of potentially unauthorized process execution using the Microsoft-signed Windows Performance Toolkit utility XBootMgrSleep.exe to bypass security controls.","title":"Suspicious Child Process Execution via XBootMgrSleep.exe","url":"https://feed.craftedsignal.io/briefs/2026-10-xbootmgrsleep-spawn/"}],"language":"en","title":"CraftedSignal Threat Feed - Windows-Performance-Toolkit","version":"https://jsonfeed.org/version/1.1"}