跳到正文

TwoSevenOneT

EDRChoker

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

这篇是英文原文

下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

EDRChoker

EDRChoker uses Policy-based Quality of Service (QoS) to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.

The rules take effect immediately and persist after the target reboots Windows.

EDRChoker relies on Windows’ pacer.sys driver.

Command Line Syntax

EDRChoker.exe `

To create QoS Policy for all process name in ListFile - Each line per process

EDRChoker.exe

To remove all installed QoS Policy

EDRChoker: Choking The Telemetry Stream to Bypass Defenses

Some EDR/Antivirus have been successfully tested

  • Elastic Defend
  • Microsoft Defender for Endpoint (MDE)
  • Tanium Threat Response Agent (EDR)
  • Trendmicro Deep Security Agent
  • Hurukai (HarfangLab EDR)
  • Cortex XDR
  • …
  • Please contact me if you successfully test it against any other EDR.

Demo Video

Youtube EDRChoker: https://youtu.be/hj05mT-45bo

🐦 Enjoying my work? Support the journey by following me on X

图片:Twitter Follow

Author:

Two Seven One Three

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。