Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

New Tool EDRChoker Disrupts EDR Agents via QoS Throttling

Posted on June 7, 2026 By CWS

A new open-source tool, EDRChoker, has emerged as a novel solution for undermining Endpoint Detection and Response (EDR) agents. This tool, rather than terminating processes or injecting code, uses Windows’ Policy-Based Quality of Service (QoS) to significantly reduce network bandwidth, effectively isolating EDR agents from their cloud management systems.

Innovative Strategy for EDR Interference

Crafted by the security researcher known as @TwoSevenOneT, EDRChoker leverages Windows’ native QoS capabilities to throttle the bandwidth of EDR processes nearly to zero. This method renders EDR agents incapable of maintaining their essential connection with cloud-based management servers, which are vital for data collection, threat analysis, and administrative oversight.

By severing this connection, EDR agents are effectively rendered inactive, unable to alert on threats or receive updates and commands from network administrators. This inherent dependency on cloud connectivity is the precise vulnerability that EDRChoker exploits.

Technical Mechanisms Behind EDRChoker

Traditionally, red teams have utilized methods such as Windows Defender Firewall rules and Windows Filtering Platform API calls to disrupt EDR communications. Tools like EDRSilencer deploy the FwpmFilterAdd0 API to block EDR packets selectively. However, these methods often trigger forensic alerts due to packet blocking and dropping, which are detected by security platforms.

EDRChoker employs a different tactic by using the New-NetQosPolicy command to throttle EDR processes to 8 bits per second. This rate is insufficient for completing even a basic TLS handshake, causing EDR agents to time out without generating detectable firewall events. The effectiveness lies in its use of pacer.sys, an NDIS Lightweight Filter Driver that operates at a lower level in the network stack than traditional filtering methods.

Implications for Cybersecurity Defense

EDRChoker’s technique highlights a significant vulnerability in EDR systems that rely heavily on constant cloud connectivity. As attackers exploit deeper layers of the Windows network stack, it becomes crucial for defenders to enhance their monitoring strategies to prevent potential blind spots in security operations.

The tool, available on GitHub, offers two operating modes: ‘Remove mode’ for purging existing QoS policies and ‘Install mode’ for generating new, uniquely named QoS policies based on EDR process names. This ensures that no two deployments are identical, complicating detection efforts.

In summary, EDRChoker serves as a reminder of the critical need for robust cybersecurity practices that anticipate and mitigate sophisticated tactics targeting network vulnerabilities.

Cyber Security News Tags:cloud connectivity, Cybersecurity, EDR, EDRChoker, endpoint detection, network security, network throttling, QoS, red team tools, security research

Post navigation

Previous Post: Emphere Secures $2.1M to Enhance AI Security Solutions
Next Post: Hackers Exploit Claude Code to Steal OAuth Tokens

Related Posts

ThreatBook Peer-Recognized as a Strong Performer in the 2025 Gartner® Peer Insights™ Voice of the Customer for Network Detection and Response — for the Third Consecutive Year ThreatBook Peer-Recognized as a Strong Performer in the 2025 Gartner® Peer Insights™ Voice of the Customer for Network Detection and Response — for the Third Consecutive Year Cyber Security News
93+ Billion Stolen Users’ Cookies Flooded by Hackers on the Dark Web 93+ Billion Stolen Users’ Cookies Flooded by Hackers on the Dark Web Cyber Security News
Weaponized ScreenConnect RMM Tool Tricks Users into Downloading Xworm RAT Weaponized ScreenConnect RMM Tool Tricks Users into Downloading Xworm RAT Cyber Security News
Sophisticated Skitnet Malware Actively Adopted by Ransomware Gangs to Streamline Operations Sophisticated Skitnet Malware Actively Adopted by Ransomware Gangs to Streamline Operations Cyber Security News
Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data Cyber Security News
North Korean Hackers Stealthy Linux Malware Leaked Online North Korean Hackers Stealthy Linux Malware Leaked Online Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark