Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

Posted on June 7, 2026 By CWS

A new open-source tool, EDRChoker, has emerged as a novel solution for undermining Endpoint Detection and Response (EDR) agents. This tool, rather than terminating processes or injecting code, uses Windows’ Policy-Based Quality of Service (QoS) to significantly reduce network bandwidth, effectively isolating EDR agents from their cloud management systems.

Innovative Strategy for EDR Interference

Crafted by the security researcher known as @TwoSevenOneT, EDRChoker leverages Windows’ native QoS capabilities to throttle the bandwidth of EDR processes nearly to zero. This method renders EDR agents incapable of maintaining their essential connection with cloud-based management servers, which are vital for data collection, threat analysis, and administrative oversight.

By severing this connection, EDR agents are effectively rendered inactive, unable to alert on threats or receive updates and commands from network administrators. This inherent dependency on cloud connectivity is the precise vulnerability that EDRChoker exploits.

Technical Mechanisms Behind EDRChoker

Traditionally, red teams have utilized methods such as Windows Defender Firewall rules and Windows Filtering Platform API calls to disrupt EDR communications. Tools like EDRSilencer deploy the FwpmFilterAdd0 API to block EDR packets selectively. However, these methods often trigger forensic alerts due to packet blocking and dropping, which are detected by security platforms.

EDRChoker employs a different tactic by using the New-NetQosPolicy command to throttle EDR processes to 8 bits per second. This rate is insufficient for completing even a basic TLS handshake, causing EDR agents to time out without generating detectable firewall events. The effectiveness lies in its use of pacer.sys, an NDIS Lightweight Filter Driver that operates at a lower level in the network stack than traditional filtering methods.

Implications for Cybersecurity Defense

EDRChoker’s technique highlights a significant vulnerability in EDR systems that rely heavily on constant cloud connectivity. As attackers exploit deeper layers of the Windows network stack, it becomes crucial for defenders to enhance their monitoring strategies to prevent potential blind spots in security operations.

The tool, available on GitHub, offers two operating modes: ‘Remove mode’ for purging existing QoS policies and ‘Install mode’ for generating new, uniquely named QoS policies based on EDR process names. This ensures that no two deployments are identical, complicating detection efforts.

In summary, EDRChoker serves as a reminder of the critical need for robust cybersecurity practices that anticipate and mitigate sophisticated tactics targeting network vulnerabilities.

Cyber Security News Tags:cloud connectivity, Cybersecurity, EDR, EDRChoker, endpoint detection, network security, network throttling, QoS, red team tools, security research

Post navigation

Previous Post: Emphere Secures $2.1M to Enhance AI Security Solutions

Related Posts

Ferocious Kitten APT Deploying MarkiRAT to Capture Keystroke and Clipboard Logging Ferocious Kitten APT Deploying MarkiRAT to Capture Keystroke and Clipboard Logging Cyber Security News
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks Cyber Security News
Threat Actors Poses as Korean TV Programs Writer to Trick Victims and Install Malware Threat Actors Poses as Korean TV Programs Writer to Trick Victims and Install Malware Cyber Security News
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement Cyber Security News
Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Critical Cybersecurity Threats: PayPal, Chrome, BeyondTrust Cyber Security News
Microsoft Reveals Techniques To Defending Against Advancing AiTM Attacks Microsoft Reveals Techniques To Defending Against Advancing AiTM Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark