Skip to content
Security

Event ID 4826: Boot configuration loaded

Boot Configuration Data loadedSecurity event 4826 records the Boot Configuration Data settings loaded at startup, such as test signing, integrity checks and kernel debugging.
4826
Event ID
4826
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
System
Default logging
Logged by default

What event 4826 means

Event 4826 is written at every boot, when Windows loads its Boot Configuration Data (BCD). It captures a snapshot of security-relevant boot options: whether test signing is on (TestSigning), whether driver integrity checks are disabled (DisableIntegrityChecks), whether kernel or hypervisor debugging is enabled (KernelDebug, HypervisorDebug), plus flight signing and hypervisor settings.

On a healthy production system these values are the same boot after boot, and the Yes/No options are almost always No. A change to Yes — especially TestSigning or DisableIntegrityChecks — means someone ran bcdedit to weaken code-signing enforcement, which lets unsigned or test-signed drivers load. That is a technique for loading rootkits and malicious kernel drivers.

Because the event reflects settings at boot, it shows the effect of a change only after the next restart. The bcdedit command itself is best found in process creation logs.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Other Policy Change Events (Success). Microsoft documents that 4826 is logged regardless of this subcategory's setting.

Windows 8 / Server 2012 and later. Yes/No values are stored as %%1842 (Yes) and %%1843 (No) in the raw XML.

Key fields

FieldWhat it tells you
SubjectUserSidNormally S-1-5-18 (SYSTEM). Anything else is unusual.
AdvancedOptionsWhether the advanced boot options (F8) menu is set to show on the next boot.
KernelDebugWhether kernel debugging is enabled (bcdedit /debug on). Should be No outside of driver development machines.
TestSigningWhether test-signed kernel code is allowed to load (bcdedit /set testsigning on). Yes on a production host is a strong warning sign.
ValueMeaning
%%1842Yes
%%1843No
FlightSigningWhether flight-signed (Windows Insider) code is trusted.
DisableIntegrityChecksWhether driver signature integrity checks are disabled (bcdedit /set nointegritychecks on). Yes weakens kernel code-signing enforcement.
ValueMeaning
%%1842Yes
%%1843No
HypervisorLaunchTypeHypervisor launch setting, Off or Auto (the hypervisor starts at boot).
HypervisorDebugWhether hypervisor debugging is enabled.

Common benign sources

  • One record at every boot with unchanged settings.
  • Developer and driver test machines where test signing or kernel debugging is intentionally enabled.
  • Changes to hypervisor settings after enabling Hyper-V or virtualization-based security.

What attackers do that produces it

  • Enabling test signing or disabling integrity checks with bcdedit to load an unsigned or self-signed malicious driver or rootkit.
  • Enabling kernel debugging to tamper with the running kernel.

Investigation tips

  • Compare each 4826 with the previous boot's record on the same host; any Yes/No flip needs an explanation.
  • Search 4688 / Sysmon 1 before the reboot for bcdedit.exe with testsigning, nointegritychecks or debug arguments, and identify the session that ran it.
  • Check for new driver services (4697, System 7045 with ServiceType 0x1) installed around the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1553.006 Subvert Trust Controls: Code Signing Policy ModificationDefense Impairment
T1542 Pre-OS BootStealth, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading