Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)

Alerts on bcdedit.exe executions with command-line options consistent with boot configuration tampering.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
@neu5ron (SigmaHQ), DRL 1.1
Published
2019-02-07
Updated
2026-07-31

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process executions of bcdedit.exe where the command line includes parameters consistent with modifying boot configuration, such as delete/deletevalue, import, safeboot, or network. Attackers and malware may use boot configuration changes to persist across reboots or prepare for destructive activity like ransomware staging. Detection relies on Windows process creation telemetry that records the executable name and the full command line.

Related detections9 linkedT1070 — drag to rearrange
Suspicious Browser History Wipe via Rundll32 ClearMyTracksByProcess (via process_creation)
USN Change Journal Deletion via Fsutil (via process_creation)
Suspicious Salesforce Query History Deletion Anti-Forensics
Suspicious Bootkitty Rootkit Component Drop under opt via File System
Malicious Boot Configuration Tampering via bcdedit (via process_creation)
Suspicious Browser History Clearing via RunDll32 InetCpl ClearMyTracksByProcess (via process_creation)
Suspicious Clearing of hosts.deny Access Restrictions on Linux
Windows Process Creation: Command-Line Deletion of IIS Logs
Kubernetes Audit: Deleted Events
Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Pivot detection · T1070 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.