Ransomware TTP Series: RMM Tool Registered Under SafeBoot for Safe Mode Persistence (Akira)

Detects unauthorized modification or creation of registry keys under HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\ to maintain persistence for remote access/RMM tools during Safe Mode with Networking. This technique is used by Akira ransomware affiliates to evade EDR and security software.