New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting code, but by quietly choking their network bandwidth to near-zero using Windows’ native Policy-Based Quality of Service (QoS) engine. Developed by security researcher @TwoSevenOneT, the tool exploits Windows […]

The post New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: