SafeBoot Registry Key Deleted Via Reg.EXE — Detection Rule

Detects execution of "reg.exe" commands with the "delete" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products

Read the full analysis on IntelFusions