Malicious Safe Mode Boot Configuration via bcdedit

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects bcdedit configuring the system to boot into Safe Mode by setting the safeboot option, a defense-impairment technique observed in an EDR analysis of LockBit ransomware that forced Safe Mode to disable security tooling before encryption. It captures tampering with boot configuration to weaken host defenses. Detecting this is important because interactive bcdedit safeboot changes are strongly associated with ransomware attempting to evade protection prior to file encryption.

Related detections4 linkedT1688 — drag to rearrange
Malicious Removal of Defender Safe Mode Service Registration via Process Creation
Malicious Boot Configuration Set to Safe Mode with Networking via bcdedit
Suspicious Boot Configuration Change to Safeboot Minimal via bcdedit
Malicious Safe Mode Boot Configuration via bcdedit for Defense Evasion via Process Creation
Malicious Safe Mode Boot Configuration via bcdedit
Pivot detection · T1688 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.