Skip to content

TwoSevenOneT/EDRChoker

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

EDRChoker

EDRChoker uses Policy-based Quality of Service (QoS) to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.

The rules take effect immediately and persist after the target reboots Windows.

EDRChoker relies on Windows' pacer.sys driver.

Command Line Syntax

EDRChoker.exe <ListFile>

To create QoS Policy for all process name in ListFile - Each line per process

EDRChoker.exe

To remove all installed QoS Policy

Links

EDRChoker: Choking The Telemetry Stream to Bypass Defenses

Some EDR/Antivirus have been successfully tested

  • Elastic Defend
  • ...
  • Please contact me if you successfully test it against any other EDR.

Demo Video

Youtube EDRChoker: https://youtu.be/hj05mT-45bo

🐦 Enjoying my work? Support the journey by following me on X

Twitter Follow

Author:

Two Seven One Three

About

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

Resources

Stars

Watchers

Forks

Packages

 
 
 

Contributors

Languages