Secure AF - A Cybersecurity Podcast

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

Alias Cybersecurity

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 5:43

Got a question or comment? Message us here!

Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.

Support the show

Watch full episodes at youtube.com/@aliascybersecurity.
Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

Secure After Dark Artwork

Secure After Dark

Alias Cybersecurity