Registry Persistence via Service in Safe Mode

 Original Source: [Sigma source]
Title: Registry Persistence via Service in Safe Mode
Status: test
Description:Detects the modification of the registry to allow a driver or service to persist in Safe Mode.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-33---windows-add-registry-value-to-load-service-in-safe-mode-without-network
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1112/T1112.md#atomic-test-34---windows-add-registry-value-to-load-service-in-safe-mode-with-network
Author: frack113
Date: 2022-04-04
modified:2025-10-22
Tags:
  • -'attack.stealth'
  • -'attack.t1564.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains:
      -'\Control\SafeBoot\Minimal\'
      -'\Control\SafeBoot\Network\'

    TargetObject|endswith: '\(Default)'
    Details: 'Service'
  filter_optional_sophos:
    Image: 'C:\WINDOWS\system32\msiexec.exe'
    TargetObject|endswith:
      -'\Control\SafeBoot\Minimal\SAVService\(Default)'
      -'\Control\SafeBoot\Network\SAVService\(Default)'

  filter_optional_mbamservice:
    Image|endswith: '\MBAMInstallerService.exe'
    TargetObject|endswith: '\MBAMService\(Default)'
    Details: 'Service'
  filter_optional_hexnode:
    Image: 'C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe'
    TargetObject|endswith:
      -'\Control\SafeBoot\Minimal\Hexnode Updater\(Default)'
      -'\Control\SafeBoot\Network\Hexnode Updater\(Default)'
      -'\Control\SafeBoot\Minimal\Hexnode Agent\(Default)'
      -'\Control\SafeBoot\Network\Hexnode Agent\(Default)'

    Details: 'Service'
  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high