EDRChoker: Choking The Telemetry Stream to Bypass Defenses (opens in new tab) 聽馃摗MQTT 聽Content type: Blog
EDRChoker redteam tool uses Policy-based QoS - pacer.sys to set throttling on EDR agents, causing them to always time out, effectively blocking them
Read the original article