Boot Configuration Tampering Via Bcdedit.EXE — Detection Rule

Detects the use of the bcdedit command to tamper with the boot configuration data. This technique is often times used by malware or attackers as a destructive way before launching ransomware.

Read the full analysis on IntelFusions