Safe Mode Boot T1688

Tactic: Defense Impairment

Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot.

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine1in 1* /s*, *-s*
OriginalFileName1eq 1mountvol.exe
process_name1eq 1mountvol.exe

Top indicator values (4 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinein
* /s*
12
CommandLinein
*-s*
15
OriginalFileNameeq
mountvol.exe
1
process_nameeq
mountvol.exe
12

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Splunk 1 rule