Tag
medium
advisory
Detection of Bcdedit Boot Configuration Modification
2 rules 1 TTPThis rule identifies the use of bcdedit.exe to modify boot configuration data, which may be indicative of a destructive attack or ransomware activity aimed at inhibiting system recovery by disabling error recovery or ignoring boot failures.
Microsoft Defender XDR +2
boot-configuration
bcdedit
impact
windows
2r
1t
high
advisory
BCDEdit Failure Recovery Modification
2 rules 1 TTPDetection of modifications to Windows error recovery boot configurations using bcdedit.exe, a technique commonly used by ransomware to disable system restoration options.
Windows
bcdedit
boot-configuration
ransomware
2r
1t