EDR Telemetry Disruption via QoS Policies
Score: 9/10

EDR Telemetry Disruption via QoS Policies

Threat actors can abuse Windows Quality of Service (QoS) policies via PowerShell or WMI to throttle EDR agent outbound bandwidth to near zero, effectively silencing cloud-based telemetry.

Executive Summary

Recent analysis highlights a technique where attackers with administrative privileges utilize Windows Quality of Service (QoS) policies to disrupt Endpoint Detection and Response (EDR) communications. By creating policies that limit a specific EDR process's outbound bandwidth to extremely low levels (e.g., 8 bits per second), the agent is unable to complete TLS handshakes with its cloud console, leading to a loss of remote visibility and alerting capabilities.

Technically, this is achieved through the New-NetQosPolicy PowerShell cmdlet or direct WMI manipulation of the MSFT_NetQosPolicySettingData class. Tools like EDRChoker automate this by targeting a pre-defined list of common EDR binaries. This method is distinct from traditional 'EDR silencing' as it does not drop packets but instead chokes the bandwidth, often leaving the agent appearing 'healthy' in management consoles while failing to transmit telemetry.

This technique significantly impacts an organization's Mean-Time-To-Detect (MTTD) by blinding SOC teams during an active breach. While local EDR prevention rules may still function, the lack of centralized reporting prevents coordinated incident response and cross-enterprise threat hunting.

Key Details

Threat Name

EDRChoker

Affects

—

Adversary

—

MITRE Techniques

Malware/Tools

EDRChoker, EDRUnChoker

Report Score

9out of 10
Quality Score
Excellent
IOC Quality5
TTP Details9
Detection Guidance10
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources