A recent incident involving Akira ransomware affiliates has revealed a notable tactic: disabling endpoint detection and response (EDR) solutions by rebooting compromised systems into Safe Mode with Networking. This approach allowed the attackers to evade detection and steal sensitive data. Notably, the attackers failed to encrypt the stolen data, suggesting a potential misstep in their operational planning. The use of Safe Mode to disable EDR solutions highlights the ongoing cat-and-mouse game between attackers and defenders, with each side continually adapting and evolving their tactics. The fact that Akira affiliates are targeting EDR solutions specifically1 indicates a growing awareness of the importance of these tools in detecting and preventing ransomware attacks. This development matters to security practitioners because it underscores the need for robust operational resilience planning to mitigate the impact of such attacks.