Title:Add SafeBoot Keys Via Reg Utility Status:test Description:Detects execution of "reg.exe" commands with the "add" or "copy" flags on safe boot registry keys. Often used by attacker to allow the ransomware to work in safe mode as some security products do not References: -https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/ Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-09-02 modified:2024-03-19 Tags: