QoS Registry Policy Modification
Detects modifications to the Windows QoS Group Policy registry hive, which can be used as a persistence mechanism for EDR throttling or other malicious purposes. This rule specifically looks for any registry events within the 'SOFTWARE\Policies\Microsoft\Windows\QoS' path.
Microsoft Sentinel (KQL)

