EDRChoker Tool Disrupts Endpoint Detection Using Windows QoS Policies
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The EDRChoker tool, recently released as an open-source red team utility, disrupts Endpoint Detection and Response (EDR) systems by manipulating Windows' Policy-Based Quality of Service (QoS) settings. This innovative method reduces network bandwidth to near-zero, effectively silencing EDR agents without traditional evasion techniques like process termination or code injection. Developed by security researcher @TwoSevenOneT, EDRChoker poses a significant threat to organizations relying on cloud-connected EDR solutions. The tool's unique approach is gaining attention in the cybersecurity community, highlighting the need for enhanced defenses against such tactics. Currently, there are no specific CVEs associated with this tool, but its implications for endpoint security are considerable.
Key Points: • EDRChoker disrupts EDR systems by choking network bandwidth using Windows QoS. • The tool is open-source and developed by researcher @TwoSevenOneT. • Organizations using cloud-connected EDR solutions are particularly vulnerable.