logo

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

ID: 96932277-bafb-5345-8192-9a965d7a14d4

STIX ID: report--96932277-bafb-5345-8192-9a965d7a14d4

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Guru Baran

...
...

**EDRChoker** is an open-source red-team tool that leverages Windows Policy-Based Quality of Service (QoS) via pacer.sys to throttle EDR agent network traffic to near-zero, preventing cloud-connected EDR agents from completing TLS handshakes or contacting their management servers and thereby evading WFP-level detections; the tool auto-generates per-process GUID-named QoS policies that persist across reboots and includes install and remove modes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.