QoS Policy Targeting EDR Processes

Detects the creation of Windows QoS policies that specifically target EDR, antivirus, or security monitoring processes using the -AppPathNameMatchCondition parameter. This technique can be used to throttle security tool network traffic, reducing telemetry visibility and impairing detection capabilities.

Microsoft Sentinel (KQL)