Safe Mode Boot

T1688

Technique.View on attack.mitre.org

About this technique

Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot.

Adversaries may abuse safe mode to disable endpoint defenses that may not start with a limited boot. Hosts can be forced into safe mode after the next reboot via modifications to Boot Configuration Data (BCD) stores, which are files that manage boot application settings.

Adversaries may also add their malicious applications to the list of minimal services that start in safe mode by modifying relevant Registry values (i.e. Modify Registry). Malicious Component Object Model (COM) objects may also be registered and loaded in safe mode.

Detection rules1

Rules on DetectionCode tagged with T1688.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Windows EFI Volume Mount Attempt Via MountvolAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software7

Campaigns0

None recorded.

Procedure examples7

Software7

Used byProcedure example
MalwareAvosLocker

AvosLocker can restart a compromised machine in safe mode.

MalwareBlack Basta

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.

MalwareEmbargo

Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode.

MalwareLockBit 3.0

LockBit 3.0 can reboot the infected host into Safe Mode.

MalwareQilin

Qilin can reboot targeted systems in safe mode to avoid detection.

MalwareRansomHub

RansomHub can reboot targeted systems into Safe Mode prior to encryption.

MalwareREvil

REvil can force a reboot in safe mode with networking.

References6

  1. BleepingComputer REvil 2021 Open source
    Abrams, L. (2021, March 19). REvil ransomware has a new ‘Windows Safe Mode’ encryption mode. Retrieved June 23, 2021.
  2. CyberArk Labs Safe Mode 2016 Open source
    Naim, D.. (2016, September 15). CyberArk Labs: From Safe Mode to Domain Compromise. Retrieved June 23, 2021.
  3. Cybereason safe mode boot Open source
    Cybereason Nocturnus. (n.d.). Cybereason vs. MedusaLocker Ransomware. Retrieved April 15, 2026.
  4. Microsoft Windows Startup Settings Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  5. Microsoft bcdedit Open source
    Microsoft. (n.d.). Retrieved April 15, 2026.
  6. Sophos Safe Mode Boot Open source
    Andrew Brandt. (2019, December 9). Snatch ransomware reboots PCs into Safe Mode to bypass protection. Retrieved April 15, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.