Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

Posted on June 7, 2026 By CWS

A new open-source tool, EDRChoker, has emerged as a novel solution for undermining Endpoint Detection and Response (EDR) agents. This tool, rather than terminating processes or injecting code, uses Windows’ Policy-Based Quality of Service (QoS) to significantly reduce network bandwidth, effectively isolating EDR agents from their cloud management systems.

Innovative Strategy for EDR Interference

Crafted by the security researcher known as @TwoSevenOneT, EDRChoker leverages Windows’ native QoS capabilities to throttle the bandwidth of EDR processes nearly to zero. This method renders EDR agents incapable of maintaining their essential connection with cloud-based management servers, which are vital for data collection, threat analysis, and administrative oversight.

By severing this connection, EDR agents are effectively rendered inactive, unable to alert on threats or receive updates and commands from network administrators. This inherent dependency on cloud connectivity is the precise vulnerability that EDRChoker exploits.

Technical Mechanisms Behind EDRChoker

Traditionally, red teams have utilized methods such as Windows Defender Firewall rules and Windows Filtering Platform API calls to disrupt EDR communications. Tools like EDRSilencer deploy the FwpmFilterAdd0 API to block EDR packets selectively. However, these methods often trigger forensic alerts due to packet blocking and dropping, which are detected by security platforms.

EDRChoker employs a different tactic by using the New-NetQosPolicy command to throttle EDR processes to 8 bits per second. This rate is insufficient for completing even a basic TLS handshake, causing EDR agents to time out without generating detectable firewall events. The effectiveness lies in its use of pacer.sys, an NDIS Lightweight Filter Driver that operates at a lower level in the network stack than traditional filtering methods.

Implications for Cybersecurity Defense

EDRChoker’s technique highlights a significant vulnerability in EDR systems that rely heavily on constant cloud connectivity. As attackers exploit deeper layers of the Windows network stack, it becomes crucial for defenders to enhance their monitoring strategies to prevent potential blind spots in security operations.

The tool, available on GitHub, offers two operating modes: ‘Remove mode’ for purging existing QoS policies and ‘Install mode’ for generating new, uniquely named QoS policies based on EDR process names. This ensures that no two deployments are identical, complicating detection efforts.

In summary, EDRChoker serves as a reminder of the critical need for robust cybersecurity practices that anticipate and mitigate sophisticated tactics targeting network vulnerabilities.

Cyber Security News Tags:cloud connectivity, Cybersecurity, EDR, EDRChoker, endpoint detection, network security, network throttling, QoS, red team tools, security research

Post navigation

Previous Post: Emphere Secures $2.1M to Enhance AI Security Solutions
Next Post: Hackers Exploit Claude Code to Steal OAuth Tokens

Related Posts

New Research Unmask DPRK IT Workers Email Address and Hiring Patterns New Research Unmask DPRK IT Workers Email Address and Hiring Patterns Cyber Security News
Odyssey Stealer Escalates Threats to macOS Users Odyssey Stealer Escalates Threats to macOS Users Cyber Security News
AWS and Anthropic Enhance AI Cybersecurity with Claude Mythos AWS and Anthropic Enhance AI Cybersecurity with Claude Mythos Cyber Security News
Critical Vulnerability in SonicWall Appliances Exposes Networks Critical Vulnerability in SonicWall Appliances Exposes Networks Cyber Security News
WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent Cyber Security News
Threat Actors Attacking Fans and Teams of Belgian Grand Prix With Phishing Campaigns Threat Actors Attacking Fans and Teams of Belgian Grand Prix With Phishing Campaigns Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Target South Korean Firms with Backdoor
  • Nightmare Eclipse Reveals Zero-Day Flaws in Major Software
  • OpenVPN Enhances Security with Critical Update
  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Target South Korean Firms with Backdoor
  • Nightmare Eclipse Reveals Zero-Day Flaws in Major Software
  • OpenVPN Enhances Security with Critical Update
  • Telerik Vulnerability Chain Allows Remote Code Execution
  • Urgent N-able Hotfix Addresses Critical Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark