EDRChoker uses Policy-based Quality of Service (QoS) to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.
The rules take effect immediately and persist after the target reboots Windows.
EDRChoker relies on Windows' pacer.sys driver.
EDRChoker.exe <ListFile>
To create QoS Policy for all process name in ListFile - Each line per process
EDRChoker.exe
To remove all installed QoS Policy
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
- Elastic Defend
- ...
- Please contact me if you successfully test it against any other EDR.
Youtube EDRChoker: https://youtu.be/hj05mT-45bo