EDRUnChoker
Fileless WMI remediation for EDRChoker counters QoS abuse (pacer.sys) that throttles EDR agents to near-zero network bandwidth.
Registers a permanent subscription in root\subscription (no files on disk). A 5-second timer runs embedded VBScript that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles.
Scripts
| Script | Purpose |
|---|---|
Install-EdrChokerWmiDefense.ps1 |
Deploy subscription (elevated) |
Uninstall-EdrChokerWmiDefense.ps1 |
Remove subscription |
Get-EdrChokerDefenseStatus.ps1 |
Check subscription and policy count |
Quick start
.\Install-EdrChokerWmiDefense.ps1
.\Get-EdrChokerDefenseStatus.ps1
SOC / event log
Each successful cleanup writes a Warning to the Application log under source EDRChokerDefense. One event is emitted per removed policy, useful as remediation evidence and to correlate with EDRChoker activity on the host.
| Event ID | Meaning |
|---|---|
| 1000 | Subscription installed |
| 1001 | Subscription removed |
| 1002 | Malicious QoS policy removed |
| 1003 | Remediation failed |
1002 example: action=remediate qos_policy=02zxnnzr target=elastic-endpoint.exe throttle_bps=8 tier=tier1-known-edr instance_id={...}
Get-WinEvent -FilterHashtable @{ LogName='Application'; ProviderName='EDRChokerDefense' } -MaxEvents 50
Forward ProviderName="EDRChokerDefense" via WEF, Splunk UF, Elastic Agent, etc.
Protect the subscription
Attackers may delete or modify the WMI objects in root\subscription to disable defense. Baseline the subscription after install and alert on changes.
Sysmon (recommended): enable and monitor:
| Sysmon ID | What to watch |
|---|---|
| 19 | WmiEventFilter created/modified/deleted |
| 20 | WmiEventConsumer created/modified/deleted |
| 21 | WmiEventFilter ↔ consumer binding changes |
Alert on any activity involving EDRChokerDefense_QoSFilter, EDRChokerDefense_QoSConsumer, or EDRChokerDefense_Timer, and on new ActiveScriptEventConsumer / CommandLineEventConsumer instances outside your change window.
Periodic validation (GPO/script): Get-WmiObject -Namespace root\subscription -Class __EventFilter | Where-Object Name -like 'EDRChokerDefense*'