{
  "technique_id": "T1688",
  "name": "Safe Mode Boot",
  "tactics": [
    "Defense Impairment"
  ],
  "platforms": [
    "Windows"
  ],
  "summary": "Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot...",
  "generated_by": "SOC Response Atlas by Basyrix"
}