TwoSevenOneT
EDRChoker
A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
Documentation snapshot
README 快照
翻译暂时拿不到。
机器翻译的项目简介,仅供参考。原文在下方,也可以直接用浏览器自带的整页翻译 (Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」)。
下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。
本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。
EDRChoker
EDRChoker uses Policy-based Quality of Service (QoS) to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.
The rules take effect immediately and persist after the target reboots Windows.
EDRChoker relies on Windows’ pacer.sys driver.
Command Line Syntax
EDRChoker.exe `
To create QoS Policy for all process name in ListFile - Each line per process
EDRChoker.exe
To remove all installed QoS Policy
Links
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
Some EDR/Antivirus have been successfully tested
- Elastic Defend
- Microsoft Defender for Endpoint (MDE)
- Tanium Threat Response Agent (EDR)
- Trendmicro Deep Security Agent
- Hurukai (HarfangLab EDR)
- Cortex XDR
- …
- Please contact me if you successfully test it against any other EDR.
Demo Video
Youtube EDRChoker: https://youtu.be/hj05mT-45bo
🐦 Enjoying my work? Support the journey by following me on X
Author:
Official distribution
获取与安装
暂未发现可确认的官方软件包地址
当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。
本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。
Before installing
使用前核验
本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。