Ransomware TTP Series: Safe Mode Boot Reconfiguration via bcdedit for EDR Evasion (Akira)
Detects the use of the bcdedit.exe utility to configure the Windows boot configuration to enter Safe Mode (minimal or with networking), immediately followed by the execution of a shutdown command with the reboot flag. This sequence is a known technique utilized by Akira ransomware affiliates to force a system reboot into a restricted environment where security agents and endpoint detection and response (EDR) tools may fail to load, allowing for undetected encryption.
YARA-L

