Event ID 4826: Boot configuration loaded
- Event ID
- 4826
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- System
- Default logging
- Logged by default
What event 4826 means
Event 4826 is written at every boot, when Windows loads its Boot Configuration Data (BCD). It captures a snapshot of security-relevant boot options: whether test signing is on (TestSigning), whether driver integrity checks are disabled (DisableIntegrityChecks), whether kernel or hypervisor debugging is enabled (KernelDebug, HypervisorDebug), plus flight signing and hypervisor settings.
On a healthy production system these values are the same boot after boot, and the Yes/No options are almost always No. A change to Yes — especially TestSigning or DisableIntegrityChecks — means someone ran bcdedit to weaken code-signing enforcement, which lets unsigned or test-signed drivers load. That is a technique for loading rootkits and malicious kernel drivers.
Because the event reflects settings at boot, it shows the effect of a change only after the next restart. The bcdedit command itself is best found in process creation logs.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Other Policy Change Events (Success). Microsoft documents that 4826 is logged regardless of this subcategory's setting.
Windows 8 / Server 2012 and later. Yes/No values are stored as %%1842 (Yes) and %%1843 (No) in the raw XML.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| SubjectUserSid | Normally S-1-5-18 (SYSTEM). Anything else is unusual. | ||||||
| AdvancedOptions | Whether the advanced boot options (F8) menu is set to show on the next boot. | ||||||
| KernelDebug | Whether kernel debugging is enabled (bcdedit /debug on). Should be No outside of driver development machines. | ||||||
| TestSigning | Whether test-signed kernel code is allowed to load (bcdedit /set testsigning on). Yes on a production host is a strong warning sign.
| ||||||
| FlightSigning | Whether flight-signed (Windows Insider) code is trusted. | ||||||
| DisableIntegrityChecks | Whether driver signature integrity checks are disabled (bcdedit /set nointegritychecks on). Yes weakens kernel code-signing enforcement.
| ||||||
| HypervisorLaunchType | Hypervisor launch setting, Off or Auto (the hypervisor starts at boot). | ||||||
| HypervisorDebug | Whether hypervisor debugging is enabled. |
Common benign sources
- One record at every boot with unchanged settings.
- Developer and driver test machines where test signing or kernel debugging is intentionally enabled.
- Changes to hypervisor settings after enabling Hyper-V or virtualization-based security.
What attackers do that produces it
- Enabling test signing or disabling integrity checks with
bcdeditto load an unsigned or self-signed malicious driver or rootkit. - Enabling kernel debugging to tamper with the running kernel.
Investigation tips
- Compare each 4826 with the previous boot's record on the same host; any Yes/No flip needs an explanation.
- Search 4688 / Sysmon 1 before the reboot for
bcdedit.exewithtestsigning,nointegritychecksordebugarguments, and identify the session that ran it. - Check for new driver services (4697, System 7045 with ServiceType
0x1) installed around the same time.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.