Malicious ELAM Driver Disable via Bcdedit

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-29
Updated
2026-09-29

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects bcdedit disabling Early Launch Anti-Malware drivers which prevents boot-time protection from loading and allows unsigned or malicious drivers to initialize. This tampering appears in ransomware playbooks that clear the way for kernel-level evasion. Disabling ELAM undermines the boot integrity chain that would otherwise block untrusted drivers.

Related detections9 linkedT1685 — drag to rearrange
Suspicious Windows Defender Exclusion Added via PowerShell Add-MpPreference
Suspicious Security Product Process Termination via Named Utility
Suspicious Windows Defender Disabling via SystemSettingsAdminFlows
Windows Defender Exclusion Path Added via Add-MpPreference
Suspicious Hosts File Modification to Block Security Vendors via file_event
Malicious Windows Defender Real-Time Protection Disabled via Registry
Malicious Vulnerable Driver Load via TfSysMon.sys BYOVD (via driver_load)
Suspicious Defendnot Antivirus Disabling Component Dropped in ProgramData (via file_event)
Malicious Removal of Defender Safe Mode Service Registration via Process Creation
Malicious ELAM Driver Disable via Bcdedit
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.