Episode Details
Back to Episodes
Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders
Published 1 month ago
Description
Got a question or comment? Message us here!
Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.
Watch full episodes at youtube.com/@aliascybersecurity.
Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.