EDRUnChoker Execution
Detects execution of the EDRUnChoker remediation tool, useful for situational awareness. This rule specifically looks for the command line containing 'Install-EdrChokerWmiDefense.ps1', indicating the execution of a PowerShell script related to EDR evasion or manipulation.
Microsoft Sentinel (KQL)

