Akira Affiliate Safe Mode with Networking Reboot via bcdedit
Detects the modification of boot configuration data (BCD) using bcdedit to enable 'Safe Mode with Networking' on the next reboot. Adversaries, including Akira ransomware affiliates, use this technique to bypass endpoint detection and response (EDR) solutions by ensuring they do not start when the system boots in a restricted safe mode.
Sigma

