tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.5k stars 142 forks source link

Update CrowdStrike #14

Closed thomaspatzke closed 1 year ago

thomaspatzke commented 1 year ago

Pull Request Template

Description

Please provide the below information so we can validate before merging:

  1. Does the proposed EDR feature align with our definition of telemetry?(definition here)
  2. Could you please provide documentation to support the telemetry you are proposing?(If it is held privately, please reach out to me or @inodee)
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

1: Yes 2:

3: If required I can provide this privately.

Type of change

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.

Test Configuration:

Checklist:

Don't stress yourself out, just answer the above to the best of your ability and we can discuss in the comments 🙂

tsale commented 1 year ago

Thank you for this proposed changes @thomaspatzke, they look good! The only question I have before I approve this PR is around the registry keys. You are proposing to change them to partially.

thomaspatzke commented 1 year ago

Yes, I've changed them to "Partially" because only specific keys (ASEP = "AutoStarting Entry Point") are logged and there's no possibility to log other keys.