.. /XBootMgrSleep.exe
Star

Execute (CMD)

Windows Performance Toolkit binary used for tracing and analyzing system performance during sleep and resume transitions.

Paths:

Resources:

Acknowledgements:

Execute

  1. Execute a command with XBootMgrSleep as a parent process, with a 1 second (=1000 milliseconds) delay.

    xbootmgrsleep.exe 1000 "{CMD}"
    Use case
    Performs execution of specified command, can be used as a defense evasion
    Privileges required
    User
    Operating systems
    Windows
    ATT&CK® technique
    T1202
    Tags
    Execute: CMD