Malicious Safe Mode Boot Configuration via bcdedit safeboot network (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-26
Updated
2026-09-26

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects bcdedit configuring the system to boot into Safe Mode with networking via the safeboot network option, a technique used by RansomHub to run encryption where security tools are disabled per Group-IB. Adversaries force a Safe Mode reboot to bypass endpoint defenses before encrypting, making this a strong pre-impact signal.

Related detections5 linkedT1688 — drag to rearrange
Malicious Safe Mode Boot Configuration via bcdedit
Malicious Removal of Defender Safe Mode Service Registration via Process Creation
Malicious Boot Configuration Set to Safe Mode with Networking via bcdedit
Suspicious Boot Configuration Change to Safeboot Minimal via bcdedit
Malicious Safe Mode Boot Configuration via bcdedit for Defense Evasion via Process Creation
Malicious Safe Mode Boot Configuration via bcdedit safeboot network (via process_creation)
Pivot detection · T1688 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.