Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0116 — Detection Strategy for Safe Mode Boot Abuse
DET0116

Detection Strategy for Safe Mode Boot Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0323 Analytic 0323
Windows

Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=12
[SafeBootRegistryPaths] Customize monitored registry paths for safe mode service additions.
[AllowedAdminTools] Whitelist legitimate administrative use of bcdedit/bootcfg for troubleshooting.
[TimeWindow] Correlate registry modifications and boot configuration commands within a short timeframe.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0116
STIX ID
x-mitre-detection-strategy--8c92a33f-ac2f-4ae9-9258-7a6a67922ad4
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.