Compliance Node Overview
MITRE ATT&CK T1562.009 (Safe Mode Boot) is an Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1054 Software Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1562/009/
SHA-256 integrity: 93d6bb4253fa09439375f904e1c58deaa78cd5952cdded7c02e7b644d50b1556
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1562.009: Safe Mode Boot (https://attack.mitre.org/versions/v16/techniques/T1562/009/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.