Akira bcdedit Safe Mode with Networking boot configuration change

Detects the use of bcdedit.exe to modify boot configuration data to enable Safe Mode with Networking. This technique is used by Akira ransomware affiliates to potentially disable or impair EDR and other security tooling prior to deploying the ransomware payload.