mirror of
https://github.com/TwoSevenOneT/EDRChoker
synced 2026-06-08 15:47:19 +00:00
Update README.md
This commit is contained in:
committed by
GitHub
parent
e103030ddd
commit
2661a80843
@@ -1 +1,36 @@
|
||||
# EDRChoker
|
||||
# EDRChoker
|
||||
|
||||
EDRChoker uses **Policy-based Quality of Service (QoS)** to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.
|
||||
|
||||
**The rules take effect immediately and persist after the target reboots Windows.**
|
||||
|
||||
EDRChoker relies on Windows' **pacer.sys** driver.
|
||||
|
||||
### Command Line Syntax
|
||||
|
||||
**EDRChoker.exe `<ListFile`>**
|
||||
|
||||
_To create QoS Policy for all process name in ListFile - Each line per process_
|
||||
|
||||
## Links
|
||||
|
||||
[EDRChoker: Choking The Telemetry Stream to Bypass Defenses](https://www.zerosalarium.com/2026/06/edrchoker-choking-telemetry-stream-block-edr.html)
|
||||
|
||||
### Some EDR/Antivirus have been successfully tested
|
||||
|
||||
- **Elastic Defend**
|
||||
- ...
|
||||
- _Please contact me if you successfully test it against any other EDR._
|
||||
|
||||
## Demo Video
|
||||
|
||||
Youtube EDR-Redir V1: [https://www.youtube.com/watch?v=2_tanx7RSUw](https://www.youtube.com/watch?v=2_tanx7RSUw)
|
||||
|
||||
|
||||
## 🐦 Enjoying my work? Support the journey by following me on X
|
||||
|
||||
[](https://x.com/TwoSevenOneT)
|
||||
|
||||
## Author:
|
||||
|
||||
[Two Seven One Three](https://x.com/TwoSevenOneT)
|
||||
|
||||
Reference in New Issue
Block a user