ThreatCluster

EDRChoker Tool Disrupts Endpoint Detection Using Windows QoS Policies

First seen 8 Jun 2026, 08:16 UTC CybersecuritynewsGbhackers 85% similarity 49

Article Content

Browse articles
ThreatCluster

The EDRChoker tool, recently released as an open-source red team utility, disrupts Endpoint Detection and Response (EDR) systems by manipulating Windows' Policy-Based Quality of Service (QoS) settings. This innovative method reduces network bandwidth to near-zero, effectively silencing EDR agents without traditional evasion techniques like process termination or code injection. Developed by security researcher @TwoSevenOneT, EDRChoker poses a significant threat to organizations relying on cloud-connected EDR solutions. The tool's unique approach is gaining attention in the cybersecurity community, highlighting the need for enhanced defenses against such tactics. Currently, there are no specific CVEs associated with this tool, but its implications for endpoint security are considerable.

Key Points: • EDRChoker disrupts EDR systems by choking network bandwidth using Windows QoS. • The tool is open-source and developed by researcher @TwoSevenOneT. • Organizations using cloud-connected EDR solutions are particularly vulnerable.

ThreatCluster AI

Timeline

2026-06-07
EDRChoker tool released
The open-source tool EDRChoker was introduced, utilizing Windows QoS to disrupt EDR visibility.
Cybersecuritynews
2026-06-08
EDRChoker gains attention
The cybersecurity community is alerted to EDRChoker's novel approach to EDR disruption, emphasizing its potential impact.
Gbhackers

Community

Browse all →

Tracked Entities in This Story