Skip to content

Commit db74349

Browse files
1 parent 526e40f commit db74349

File tree

1 file changed

+6
-4
lines changed

1 file changed

+6
-4
lines changed

_lolbas/OtherMSBinaries/XBootMgrSleep.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@ Description: Windows Performance Toolkit binary used for tracing and analyzing s
44
Author: Avihay Eldad
55
Created: 2024-06-13
66
Commands:
7-
- Command: xbootmgrsleep.exe 1000 "{CMD}"
8-
Description: Execute a command with XBootMgrSleep as a parent process, with a 1 second (=1000 milliseconds) delay.
9-
Usecase: Performs execution of specified command, can be used as a defense evasion
7+
- Command: xbootmgrsleep.exe 1000 {PATH:.exe}
8+
Description: Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.
9+
Usecase: Performs execution of specified executable, can be used as a defense evasion
1010
Category: Execute
1111
Privileges: User
1212
MitreID: T1202
1313
OperatingSystem: Windows
1414
Tags:
15-
- Execute: CMD
15+
- Execute: EXE
1616
Full_Path:
1717
- Path: C:\Program Files\Windows Kits\10\Windows Performance Toolkit\xbootmgrsleep.exe
1818
- Path: C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\xbootmgrsleep.exe
@@ -21,4 +21,6 @@ Resources:
2121
Acknowledgement:
2222
- Person: Avihay Eldad
2323
Handle: '@AvihayEldad'
24+
- Person: Yuval Saban
25+
Handle: '@yuvalsaban3'
2426
---

0 commit comments

Comments
 (0)