Skip to content

New Query: EDRCHOKER - QoS Policy Abuse Targeting EDR/AV Processes - #70

Merged
dweissbacher merged 1 commit into
mainfrom
submission/63ee8832-6e3b-4078-93cd-b126cd314c11
Jul 29, 2026
Merged

New Query: EDRCHOKER - QoS Policy Abuse Targeting EDR/AV Processes#70
dweissbacher merged 1 commit into
mainfrom
submission/63ee8832-6e3b-4078-93cd-b126cd314c11

Conversation

@byteray-cql-hub-bot

Copy link
Copy Markdown
Contributor

New Query Submission

Name: EDRCHOKER - QoS Policy Abuse Targeting EDR/AV Processes
Author: Aamir Muhammad
Submission ID: 63ee8832-6e3b-4078-93cd-b126cd314c11

Description

This rule detects attempts to impair defensive mechanisms by creating or modifying Quality of Service (QoS) policies that specifically target Endpoint Detection and Response (EDR) or Antivirus (AV) processes. Adversaries may use QoS policies to throttle network traffic for security products, hindering their ability to communicate with central management or cloud services, thus impairing their effectiveness.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher
dweissbacher merged commit 7dc07bc into main Jul 29, 2026
2 checks passed
@dweissbacher
dweissbacher deleted the submission/63ee8832-6e3b-4078-93cd-b126cd314c11 branch July 29, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant