If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1688 - Safe Mode Boot, Technique T168.

site address: attack.mitre.org/techniques/T1688 redirected to: attack.mitre.org/techniques/T1688

site title: Safe Mode Boot, Technique T1688 - Enterprise MITRE ATT&CK®

Our opinion (on Sunday 16 August 2026 2:10:29 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

safe, mode, boot, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
mode (29), safe (28), retrieved (18), ransomware (12), may (12), boot (11), the (10), att (10), all (10), 2026 (8), 2022 (8), can (8), and (7), enterprise (7), defenses (7), march (7), 2023 (7), with (7), #detection (6), techniques (6), 2025 (6), black (6), basta (6), windows (6), april (6), that (6), reboot (6), ics (5), mobile (5), none (5), mitre (4), are (4), software (4), data (4), june (4), adversaries (4), new (4), avoslocker (4), into (4), abuse (4), configuration (4), registry (4), disable (4), endpoint (4), version (4), start (4), cti (3), mitigations (3), sub (3), objects (3), ransomhub (3), 2024 (3), qilin (3), september (3), lockbit (3), october (3), embargo (3), 2021 (3), revil (3), via (3), description (3), networking (3), limited (3), services (3), after (3), corporation (2), registered (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), february (2), raas (2), august (2), variant (2), response (2), january (2), has (2), encryption (2), cybereason (2), microsoft (2), bcd (2), bcdedit (2), exe (2), persistence (2), safeboot (2), strategy (2), for (2), analytic (2), name (2), possible (2), machine (2), targeted (2), systems (2), security (2), set (2), redlark (2), ntt (2), communications (2), t1688 (2), also (2), malicious (2), not (2), tools (2), ckcon (2), person (2), tickets (2), faq (2), 2015, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, use, contact, reset, filters, alfano, never, sleeps, episode, evolution, modern, thomas, tracking, magdy, golang, agenda, customizes, attacks, fbi, stopransomware, jan, holman, tomas, zvara, rock, rust, elsad, threat, assessment, avertium, depth, look, gonzalez, chavez, examining, infection, routine, cyble, targeting, high, value, organizations, november, zargarov, hijacks, fax, service, costa, incident, analysis, trend, micro, research, spotlight, abrams, nocturnus, medusalocker, naim, 2016, cyberark, labs, from, domain, compromise, andrew, brandt, 2019, december, snatch, reboots, pcs, bypass, protection, references, modification, utilities, bootcfg, under, keys, defender, view, suspicious, changes, correlated, edits, enable, adversary, an0323, det0116, ensure, run, m1054, restrict, administrator, accounts, few, individuals, following, least, privilege, principles, abused, remotely, privileged, account, management, m1026, mitigation, force, s0496, prior, s1212, avoid, s1242, infected, host, s1202, used, dll, mdeployer, solutions, through, s1247, victim, machines, network, s1070, restart, compromised, s1053, procedure, examples, live, permalink, last, modified, created, jorell, magtibay, national, australia, bank, kiyohito, yamamoto, yusuke, kubo, contributors, platforms, defense, impairment, tactic, add, their, applications, list, minimal, modifying, relevant, values, com, loaded, component, object, model, modify, hosts, forced, next, modifications, stores, which, files, manage, application, settings, starts, operating, system, drivers, third, party, such, edr, booting, there, two, versions, additional, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections, technique,


Text of the page (random words):
safe mode boot technique t1688 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise safe mode boot safe mode boot adversaries may abuse windows safe mode to disable endpoint defenses safe mode starts up the windows operating system with a limited set of drivers and services third party security software such as endpoint detection and response edr tools may not start after booting windows in safe mode there are two versions of safe mode safe mode and safe mode with networking it is possible to start additional services after a safe mode boot 1 2 adversaries may abuse safe mode to disable endpoint defenses that may not start with a limited boot hosts can be forced into safe mode after the next reboot via modifications to boot configuration data bcd stores which are files that manage boot application settings 3 adversaries may also add their malicious applications to the list of minimal services that start in safe mode by modifying relevant registry values i e modify registry malicious component object model com objects may also be registered and loaded in safe mode 4 5 6 id t1688 sub techniques no sub techniques ⓘ tactic defense impairment ⓘ platforms windows contributors jorell magtibay national australia bank limited kiyohito yamamoto redlark ntt communications yusuke kubo redlark ntt communications version 1 0 created 14 april 2026 last modified 12 may 2026 version permalink live version procedure examples id name description s1053 avoslocker avoslocker can restart a compromised machine in safe mode 7 8 s1070 black basta black basta can reboot victim machines in safe mode with networking via bcdedit set safeboot network 9 10 11 12 13 s1247 embargo embargo has used a dll variant of mdeployer to disable security solutions through safe mode 14 s1202 lockbit 3 0 lockbit 3 0 can reboot the infected host into safe mode 15 s1242 qilin qilin can reboot targeted systems in safe mode to avoid detection 16 17 s1212 ransomhub ransomhub can reboot targeted systems into safe mode prior to encryption 18 s0496 revil revil can force a reboot in safe mode with networking 6 mitigations id mitigation description m1026 privileged account management restrict administrator accounts to as few individuals as possible following least privilege principles that may be abused to remotely boot a machine in safe mode 4 m1054 software configuration ensure that endpoint defenses run in safe mode 4 detection strategy id name analytic id analytic description det0116 detection strategy for safe mode boot abuse an0323 abuse of safe mode via bcd modification boot configuration utilities bcdedit exe bootcfg exe and registry persistence under safeboot keys defender view suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses references microsoft n d retrieved april 15 2026 andrew brandt 2019 december 9 snatch ransomware reboots pcs into safe mode to bypass protection retrieved april 15 2026 microsoft n d retrieved april 15 2026 naim d 2016 september 15 cyberark labs from safe mode to domain compromise retrieved june 23 2021 cybereason nocturnus n d cybereason vs medusalocker ransomware retrieved april 15 2026 abrams l 2021 march 19 revil ransomware has a new windows safe mode encryption mode retrieved june 23 2021 trend micro research 2022 april 4 ransomware spotlight avoslocker retrieved january 11 2023 costa f 2022 may 1 raas avoslocker incident response analysis retrieved january 11 2023 zargarov n 2022 may 2 new black basta ransomware hijacks windows fax service retrieved march 7 2023 cyble 2022 may 6 new ransomware variant targeting high value organizations retrieved november 17 2024 gonzalez i chavez i et al 2022 may 9 examining the black basta ransomware s infection routine retrieved march 7 2023 avertium 2022 june 1 an in depth look at black basta ransomware retrieved march 7 2023 elsad a 2022 august 25 threat assessment black basta ransomware retrieved march 8 2023 jan holman tomas zvara 2024 october 23 embargo ransomware rock n rust retrieved october 19 2025 fbi et al 2023 march 16 stopransomware lockbit 3 0 retrieved february 5 2025 magdy s et al 2022 august 25 new golang ransomware agenda customizes attacks retrieved september 26 2025 thomas w 2024 june 12 tracking adversaries the qilin raas retrieved september 26 2025 alfano v et al 2025 february 12 ransomhub never sleeps episode 1 the evolution of modern ransomware retrieved march 17 2025 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 55 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 www.cisa.gov/sites/default/files/2023-___.pdf  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1688
X-GitHub-Request-Id 3D40:14FDE0:4CA1F20:4D1186E:6A811C14
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sun, 16 Aug 2026 02:10:28 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290031-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786846229.688105,VS0,VE99
Vary Accept-Encoding
X-Fastly-Request-ID d7d78db00378075dede94ba960944488ee6c52c1
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1688/
access-control-allow-origin *
expires Sun, 16 Aug 2026 02:20:28 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id B434:1020A0:4D696D3:4DD9226:6A811C14
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 02:10:28 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290049-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786846229.826928,VS0,VE112
vary Accept-Encoding
x-fastly-request-id a20793726459ae03f043ee143261edef94ba66df
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-e4c6
expires Sun, 16 Aug 2026 02:20:29 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id B434:1020A0:4D6972A:4DD927E:6A811C14
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 02:10:29 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290049-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786846229.951286,VS0,VE123
vary Accept-Encoding
x-fastly-request-id 8a9c540591884b713822f00d81139467ed4e37bd
content-length 9336

Meta Tags

title="Safe Mode Boot, Technique T1688 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size9336
load time (s)0.678407
redirect count2
speed download13769
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"