The GlitchMod knowledge base

Shadowbooting

Development kernels have an undocumented, internal feature called "shadow booting" which allows them to enter an alternate boot chain during the boot process. By placing a specially crafted file named xboxromw2d.bin (or xboxromtw2d.bin for…

3 min readUpdated Oct 9, 2026

Development kernels have an undocumented, internal feature called "shadow booting" which allows them to enter an alternate boot chain during the boot process. By placing a specially crafted file named xboxromw2d.bin (or xboxromtw2d.bin for a Test Kit) on the root of the system's hard disk, on bootup the system will start, read this file, then reboot again, finally completing the boot sequence having loaded from the bootloaders from the file on disk. Effectively, shadowbooting allows you to run a NAND image without actually flashing the NAND.[1]

This is especially useful on a zero-fuse console, as you can flash XDKBuild to it, then shadowboot into other images. This preserves the fuses, while allowing you to use it as a devkit (with XDKBuild) or as a retail console (by shadowbooting into a retail kernel). Furthermore, there are no version restrictions placed on shadowbooted images, so you are free to shadowboot into any dashboard version.

Exclamation-triangle-fill.svgEnsure that you have a transfer cable on hand in case the shadowboot file does not properly boot, as you will be unable to boot with the hard drive plugged in.

ExShadowBoot

In October 2025, hax360 (also known as kmx360) made the shadowboot feature usable as a standalone .xex application called ExShadowBoot, compatible with both development kernels (useful if you don't want the console to auto boot the shadowboot file every time), and for the first time, retail kernels (as long as they have patches to allow booting unofficial applications).

If you would like to try it, a download link to the binaries can be found on this link. All you have to do is put the desired xboxromw2d.bin shadowboot file in the same folder as the .xex file, and run said .xex file. The ExShadowBoot.xex binary is utilized with retail consoles running FreeMyXe/XeUnshackle through Bad Update, or JTAG/RGH consoles with the standard xeBuild Glitch/Glitch2/JTAG operating system (also includes consoles running DevGL, for the few who have such a configuration), while DevShadowBoot.xex is run on real dev/test kits, or JTAG/RGH/Zero Fuse running XDKBuild or RGLoader.

Pre-made Shadowboot Images

Retail

Freeboot

Images for booting the retail kernel with Freeboot patches, similarly to running a standard Glitch/Glitch2/JTAG xeBuild NAND on a JTAG/RGH console.

These can be useful when run on a retail console with Bad Update, as they allow you to have the same OS environment as a typical JTAG/RGH system, with the added benefit of allowing access to unsecured hard drives and SSDs to be detected in the SATA port without hacks like Bad Storage.

Development

Proto

Images for booting Proto stealth server.[2][3] Make sure to place Proto.xex and Proto.ini on HDD root as well as KV.bin (decrypted or encrypted KV works) and cpukey.txt (containing your CPU key).

RGLoader

Images for booting RGLoader on a real devkit. Copy all contents to root of hard drive.

Pre-made Shadowboot Images for Test Kits

None yet!

Creating Shadowboot Images

See this page for information on how to create shadowboots.

References