The approach is not entirely new. Huntress pointed to ransomware families, including Snatch and AvosLocker, that have used Safe Mode to disable defenses for years. MITRE ATT&CK tracks the behaviour as T1688, impair Defenses: Safe Mode Boot. Akira picking up… Read More "Akira ransomware reboots into Windows Safe Mode to knock EDR offline"