Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
FreeUnreviewedSigmahighv1
windows-registry-service-persistence-via-safeboot-control-keys-1547e27c
title: Windows Registry Service Persistence via SafeBoot Control Keys
id: 519d241c-b74e-4ad1-a2d2-b17e72224c39
status: test
description: This rule identifies registry changes that configure a Windows service to load during Safe Mode by writing to SafeBoot Minimal/Network control paths. Such persistence can help malicious services start when normal startup or networking defenses are reduced. It relies on registry set telemetry and matches changes to TargetObject entries under \Control\SafeBoot\Minimal\ or \Control\SafeBoot\Network\ that specify a Service and end with the (Default) value.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-33---windows-add-registry-value-to-load-service-in-safe-mode-without-network
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-34---windows-add-registry-value-to-load-service-in-safe-mode-with-network
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_add_load_service_in_safe_mode.yml
author: frack113, Huntrule Team
date: 2022-04-04
modified: 2025-10-22
tags:
- attack.stealth
- attack.t1564.001
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains:
- \Control\SafeBoot\Minimal\
- \Control\SafeBoot\Network\
TargetObject|endswith: \(Default)
Details: Service
filter_optional_sophos:
Image: C:\WINDOWS\system32\msiexec.exe
TargetObject|endswith:
- \Control\SafeBoot\Minimal\SAVService\(Default)
- \Control\SafeBoot\Network\SAVService\(Default)
filter_optional_mbamservice:
Image|endswith: \MBAMInstallerService.exe
TargetObject|endswith: \MBAMService\(Default)
Details: Service
filter_optional_hexnode:
Image: C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe
TargetObject|endswith:
- \Control\SafeBoot\Minimal\Hexnode Updater\(Default)
- \Control\SafeBoot\Network\Hexnode Updater\(Default)
- \Control\SafeBoot\Minimal\Hexnode Agent\(Default)
- \Control\SafeBoot\Network\Hexnode Agent\(Default)
Details: Service
condition: selection and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_add_load_service_in_safe_mode/info.yml
simulation:
- type: atomic-red-team
name: Windows Add Registry Value to Load Service in Safe Mode without Network
technique: T1112
atomic_guid: 1dd59fb3-1cb3-4828-805d-cf80b4c3bbb5
- type: atomic-red-team
name: Windows Add Registry Value to Load Service in Safe Mode with Network
technique: T1112
atomic_guid: c173c948-65e5-499c-afbe-433722ed5bd4
license: DRL-1.1
related:
- id: 1547e27c-3974-43e2-a7d7-7f484fb928ec
type: derived
What it detects
This rule identifies registry changes that configure a Windows service to load during Safe Mode by writing to SafeBoot Minimal/Network control paths. Such persistence can help malicious services start when normal startup or networking defenses are reduced. It relies on registry set telemetry and matches changes to TargetObject entries under \Control\SafeBoot\Minimal\ or \Control\SafeBoot\Network\ that specify a Service and end with the (Default) value.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.