Skip to content
ThreatCluster

EDRChoker Tool Disrupts Endpoint Detection Using Windows QoS Policies

First seen 8 Jun 2026, 08:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 9, 2026 at 07:56 UTC
  • EDRChoker disrupts EDR systems by choking network bandwidth using Windows QoS.
  • The tool is open-source and developed by researcher @TwoSevenOneT.
  • Organizations using cloud-connected EDR solutions are particularly vulnerable.

The EDRChoker tool, recently released as an open-source red team utility, disrupts Endpoint Detection and Response (EDR) systems by manipulating Windows' Policy-Based Quality of Service (QoS) settings. This innovative method reduces network bandwidth to near-zero, effectively silencing EDR agents without traditional evasion techniques like process termination or code injection. Developed by security researcher @TwoSevenOneT, EDRChoker poses a significant threat to organizations relying on cloud-connected EDR solutions. The tool's unique approach is gaining attention in the cybersecurity community, highlighting the need for enhanced defenses against such tactics. Currently, there are no specific CVEs associated with this tool, but its implications for endpoint security are considerable.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 105d ago How this analysis works

Timeline

2026-06-07
EDRChoker tool released
The open-source tool EDRChoker was introduced, utilizing Windows QoS to disrupt EDR visibility.
Cybersecuritynews
2026-06-08
EDRChoker gains attention
The cybersecurity community is alerted to EDRChoker's novel approach to EDR disruption, emphasizing its potential impact.
Gbhackers

More articles in this cluster (2)