Executive Summary
Recent analysis highlights a technique where attackers with administrative privileges utilize Windows Quality of Service (QoS) policies to disrupt Endpoint Detection and Response (EDR) communications. By creating policies that limit a specific EDR process's outbound bandwidth to extremely low levels (e.g., 8 bits per second), the agent is unable to complete TLS handshakes with its cloud console, leading to a loss of remote visibility and alerting capabilities.
Technically, this is achieved through the New-NetQosPolicy PowerShell cmdlet or direct WMI manipulation of the MSFT_NetQosPolicySettingData class. Tools like EDRChoker automate this by targeting a pre-defined list of common EDR binaries. This method is distinct from traditional 'EDR silencing' as it does not drop packets but instead chokes the bandwidth, often leaving the agent appearing 'healthy' in management consoles while failing to transmit telemetry.
This technique significantly impacts an organization's Mean-Time-To-Detect (MTTD) by blinding SOC teams during an active breach. While local EDR prevention rules may still function, the lack of centralized reporting prevents coordinated incident response and cross-enterprise threat hunting.
