Windows Registry Service Persistence via SafeBoot Control Keys

Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).

FreeUnreviewedSigmahighv1
title: Windows Registry Service Persistence via SafeBoot Control Keys
id: 519d241c-b74e-4ad1-a2d2-b17e72224c39
status: test
description: This rule identifies registry changes that configure a Windows service to load during Safe Mode by writing to SafeBoot Minimal/Network control paths. Such persistence can help malicious services start when normal startup or networking defenses are reduced. It relies on registry set telemetry and matches changes to TargetObject entries under \Control\SafeBoot\Minimal\ or \Control\SafeBoot\Network\ that specify a Service and end with the (Default) value.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-33---windows-add-registry-value-to-load-service-in-safe-mode-without-network
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-34---windows-add-registry-value-to-load-service-in-safe-mode-with-network
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_add_load_service_in_safe_mode.yml
author: frack113, Huntrule Team
date: 2022-04-04
modified: 2025-10-22
tags:
  - attack.stealth
  - attack.t1564.001
logsource:
  category: registry_set
  product: windows
detection:
  selection:
    TargetObject|contains:
      - \Control\SafeBoot\Minimal\
      - \Control\SafeBoot\Network\
    TargetObject|endswith: \(Default)
    Details: Service
  filter_optional_sophos:
    Image: C:\WINDOWS\system32\msiexec.exe
    TargetObject|endswith:
      - \Control\SafeBoot\Minimal\SAVService\(Default)
      - \Control\SafeBoot\Network\SAVService\(Default)
  filter_optional_mbamservice:
    Image|endswith: \MBAMInstallerService.exe
    TargetObject|endswith: \MBAMService\(Default)
    Details: Service
  filter_optional_hexnode:
    Image: C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe
    TargetObject|endswith:
      - \Control\SafeBoot\Minimal\Hexnode Updater\(Default)
      - \Control\SafeBoot\Network\Hexnode Updater\(Default)
      - \Control\SafeBoot\Minimal\Hexnode Agent\(Default)
      - \Control\SafeBoot\Network\Hexnode Agent\(Default)
    Details: Service
  condition: selection and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
regression_tests_path: regression_data/rules/windows/registry/registry_set/registry_set_add_load_service_in_safe_mode/info.yml
simulation:
  - type: atomic-red-team
    name: Windows Add Registry Value to Load Service in Safe Mode without Network
    technique: T1112
    atomic_guid: 1dd59fb3-1cb3-4828-805d-cf80b4c3bbb5
  - type: atomic-red-team
    name: Windows Add Registry Value to Load Service in Safe Mode with Network
    technique: T1112
    atomic_guid: c173c948-65e5-499c-afbe-433722ed5bd4
license: DRL-1.1
related:
  - id: 1547e27c-3974-43e2-a7d7-7f484fb928ec
    type: derived

What it detects

This rule identifies registry changes that configure a Windows service to load during Safe Mode by writing to SafeBoot Minimal/Network control paths. Such persistence can help malicious services start when normal startup or networking defenses are reduced. It relies on registry set telemetry and matches changes to TargetObject entries under \Control\SafeBoot\Minimal\ or \Control\SafeBoot\Network\ that specify a Service and end with the (Default) value.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.