Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

Posted on June 7, 2026 By CWS

A new open-source tool, EDRChoker, has emerged as a novel solution for undermining Endpoint Detection and Response (EDR) agents. This tool, rather than terminating processes or injecting code, uses Windows’ Policy-Based Quality of Service (QoS) to significantly reduce network bandwidth, effectively isolating EDR agents from their cloud management systems.

Innovative Strategy for EDR Interference

Crafted by the security researcher known as @TwoSevenOneT, EDRChoker leverages Windows’ native QoS capabilities to throttle the bandwidth of EDR processes nearly to zero. This method renders EDR agents incapable of maintaining their essential connection with cloud-based management servers, which are vital for data collection, threat analysis, and administrative oversight.

By severing this connection, EDR agents are effectively rendered inactive, unable to alert on threats or receive updates and commands from network administrators. This inherent dependency on cloud connectivity is the precise vulnerability that EDRChoker exploits.

Technical Mechanisms Behind EDRChoker

Traditionally, red teams have utilized methods such as Windows Defender Firewall rules and Windows Filtering Platform API calls to disrupt EDR communications. Tools like EDRSilencer deploy the FwpmFilterAdd0 API to block EDR packets selectively. However, these methods often trigger forensic alerts due to packet blocking and dropping, which are detected by security platforms.

EDRChoker employs a different tactic by using the New-NetQosPolicy command to throttle EDR processes to 8 bits per second. This rate is insufficient for completing even a basic TLS handshake, causing EDR agents to time out without generating detectable firewall events. The effectiveness lies in its use of pacer.sys, an NDIS Lightweight Filter Driver that operates at a lower level in the network stack than traditional filtering methods.

Implications for Cybersecurity Defense

EDRChoker’s technique highlights a significant vulnerability in EDR systems that rely heavily on constant cloud connectivity. As attackers exploit deeper layers of the Windows network stack, it becomes crucial for defenders to enhance their monitoring strategies to prevent potential blind spots in security operations.

The tool, available on GitHub, offers two operating modes: ‘Remove mode’ for purging existing QoS policies and ‘Install mode’ for generating new, uniquely named QoS policies based on EDR process names. This ensures that no two deployments are identical, complicating detection efforts.

In summary, EDRChoker serves as a reminder of the critical need for robust cybersecurity practices that anticipate and mitigate sophisticated tactics targeting network vulnerabilities.

Cyber Security News Tags:cloud connectivity, Cybersecurity, EDR, EDRChoker, endpoint detection, network security, network throttling, QoS, red team tools, security research

Post navigation

Previous Post: Emphere Secures $2.1M to Enhance AI Security Solutions
Next Post: Hackers Exploit Claude Code to Steal OAuth Tokens

Related Posts

Singularity Linux Kernel Rootkit with New Feature Prevents Detection Singularity Linux Kernel Rootkit with New Feature Prevents Detection Cyber Security News
ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process Cyber Security News
706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online 706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online Cyber Security News
Cyberattack Hits European Commission’s AWS Account Cyberattack Hits European Commission’s AWS Account Cyber Security News
New Research Details on What Happens to Data Stolen in a Phishing Attack New Research Details on What Happens to Data Stolen in a Phishing Attack Cyber Security News
Critical Flaw in Perplexity’s Comet Browser Exploited Critical Flaw in Perplexity’s Comet Browser Exploited Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Unveils AI-Powered CodeMender for Enhanced Security
  • Abstract Secures $25M to Enhance Security Operations Platform
  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling
  • AI Models Struggle with Nuclear-Sabotage Malware Analysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Unveils AI-Powered CodeMender for Enhanced Security
  • Abstract Secures $25M to Enhance Security Operations Platform
  • Google Introduces Selfie Video for Account Access Recovery
  • Dolphin X Malware Threatens 300+ Apps with AI Profiling
  • AI Models Struggle with Nuclear-Sabotage Malware Analysis

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark