Registry Query for Safe Mode Detection (T1012)

Detects reads of HKLM\SYSTEM\CurrentControlSet\Control\SystemStartOptions, the value that stores boot parameters (e.g. NOEXECUTE=OPTIN vs SAFEBOOT:MINIMAL). Ransomware including Snatch and Qilin query this key to determine whether the host is already in Safe Mode before forcing a reboot and encrypting with AV/EDR unloaded. Treat as a high-interest hunting lead when paired within minutes with Safe Mode staging: bcdedit /set safeboot, reg add under SafeBoot\Minimal or SafeBoot\Network, or shutdown /r.