BIOC Medium

Manipulation of Windows Safe Boot configuration

Safe-boot Registry settings deletion.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:

Registry registry key name = *Control\SafeBoot AND action type = delete_registry_value Host host os = windows

Preventable: yes