tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.43k stars 141 forks source link

Crowdstrike File Opened - Yes => Partially #20

Closed NicolasSchn closed 1 year ago

NicolasSchn commented 1 year ago

Related to #12

Pull Request Template

Description

Please provide the below information so we can validate before merging:

  1. Does the proposed EDR feature align with our definition of telemetry?(definition here)
  2. Could you please provide documentation to support the telemetry you are proposing?(If it is held privately, please reach out to me or @inodee)
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

1: Yes 2: This detail is not specified in the documentation, the information was provided to me by Crowdstrike support when I was surprised not to find this event in the telemetry. Indeed, some events are generated only when EDR detects suspicious behavior in the same process tree. 3: N/A

Type of change

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.

Test Configuration:

Checklist:

Don't stress yourself out, just answer the above to the best of your ability and we can discuss in the comments 🙂