Malicious Safe Mode Boot Configuration via bcdedit for Defense Evasion via Process Creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-05-01
Updated
2026-08-28

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects bcdedit.exe forcing a minimal safe-mode boot, a technique the Embargo ransomware uses to restart the host into an environment where most security products do not run before encrypting files. Legitimate administrative use of this exact command is rare on endpoints. This indicates preparation for defense evasion and ransomware detonation.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.