Skip to content

Commit de44196

Browse files
1 parent 90a991a commit de44196

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
---
2+
Name: XBootMgrSleep.exe
3+
Description: Windows Performance Toolkit binary used for tracing and analyzing system performance during sleep and resume transitions.
4+
Author: Avihay Eldad
5+
Created: 2024-06-13
6+
Commands:
7+
- Command: xbootmgrsleep.exe 1000 "{CMD}"
8+
Description: Execute a command with XBootMgrSleep as a parent process, with a 1 second (=1000 milliseconds) delay.
9+
Usecase: Performs execution of specified command, can be used as a defense evasion
10+
Category: Execute
11+
Privileges: User
12+
MitreID: T1202
13+
OperatingSystem: Windows
14+
Tags:
15+
- Execute: CMD
16+
Full_Path:
17+
- Path: C:\Program Files\Windows Kits\10\Windows Performance Toolkit\xbootmgrsleep.exe
18+
- Path: C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\xbootmgrsleep.exe
19+
Resources:
20+
- Link: https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference
21+
Acknowledgement:
22+
- Person: Avihay Eldad
23+
Handle: '@AvihayEldad'
24+
---

0 commit comments

Comments
 (0)