Akira disables EDR by rebooting into Safe Mode before exfiltrating data
An Akira ransomware affiliate got initial access through a SonicWall VPN with no MFA, then rebooted the box into Safe Mode to neutralize EDR while exfiltrating. Huntress’s account shows an EDR is no safety net once an attacker holds valid credentials.