EDRUnChoker Execution

Detects execution of the EDRUnChoker remediation tool, useful for situational awareness. This rule specifically looks for the command line containing 'Install-EdrChokerWmiDefense.ps1', indicating the execution of a PowerShell script related to EDR evasion or manipulation.