Suspicious SafeBoot RunOnce Persistence for Safe Mode Encryption by RA World

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-06-27
Updated
2026-08-28

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects registry additions creating a RunOnce entry under the SafeBoot key, a technique the RA World ransomware group uses to force execution after rebooting the host into safe mode where security tooling is inactive. Encrypting in safe mode evades endpoint defenses that do not load there. Detecting this configuration exposes preparation for defense-evasive ransomware execution.

Related detections9 linkedT1685 — drag to rearrange
Xeno Stealer Persistence via Display Calibration Run Key
Suspicious Node.js Script Execution from AppData Roaming
Windows Defender Tampering via Set-MpPreference and Exclusions
Suspicious Windows Defender Real-Time Protection Disabled via Policy Registry by Cephalus Ransomware
Suspicious AutoAdminLogon Enabled via Winlogon Registry by RansomHub Ransomware
Suspicious PlugX Persistence via CanonPrinter Run Key (via registry_set)
Suspicious Microsoft Defender Path Exclusion of User Directories (via process_creation)
Malicious Windows Defender Tampering via Set-MpPreference (via process_creation)
Malicious Container Runtime Tampering via chmod on runc (via process_creation)
Suspicious SafeBoot RunOnce Persistence for Safe Mode Encryption by RA World
Pivot detection · T1685 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.