EDR-Freeze: WerFaultSecure.exe abused to suspend security processes
Detects the abuse of WerFaultSecure.exe or similar Windows Error Reporting processes, invoked with debugging or dumping flags against security/EDR process names, or spawned by unexpected parent processes. This technique is often used to freeze security tools (EDR-Freeze) by exploiting process suspension via mini-dump handles.
Microsoft Sentinel (KQL)

