Safe Mode is not actually a protected environment. Programs can modify what launches in it if they get Admin permission. Most don't bother. Definitely an interesting alert artifact but you're usually 100% hosed at that point. My Sysmon configuration monitors for these changes.https://twitter.com/BleepinComputer/status/1379888309569257475 …
safe mode is everything i wish HVIC was. easy to use you know when it is in effect you can still run any usermode app you want you dont have to google up powershell cmds dont load all the crap drivers