BIOC
Medium
✕
Manipulation of Windows Safe Boot configuration
Safe-boot Registry settings deletion.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:
Registry registry key name = *Control\SafeBoot AND action type = delete_registry_value Host host os = windows
Preventable: yes