Secure AF - A Cybersecurity Podcast

← Secure AF - A Cybersecurity Podcast20 aug · 6 min

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders20 aug6 min

Got a question or comment? Message us here! Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes. Support the show Watch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spot...