AN0323
Analytic 0323
Windows
Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses.
WinEventLog:Security
EventCode=4688
WinEventLog:Sysmon
EventCode=13, 14
WinEventLog:Sysmon
EventCode=12
[SafeBootRegistryPaths]
Customize monitored registry paths for safe mode service additions.
[AllowedAdminTools]
Whitelist legitimate administrative use of bcdedit/bootcfg for troubleshooting.
[TimeWindow]
Correlate registry modifications and boot configuration commands within a short timeframe.