tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.43k stars 141 forks source link

modified included telemetry requiring enablement #33

Closed xC0uNt3r7hr34t closed 1 year ago

xC0uNt3r7hr34t commented 1 year ago

Update SentinelOne with Features needing to be enabled

Description

Please provide the below information so we can validate before merging:

  1. Does the proposed EDR feature align with our definition of telemetry? YES
  2. Could you please provide documentation to support the telemetry you are proposing? --- documention previously provided; telemetry switched to "Via EnablingTelemetry" due to requiring it to be turned on to be collected. It is still included with no extra cost or licensing required.
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.

Tests were not rerun due to only change being moving the previous configuration of "yes" to "Via EnablingTelemetry"

Checklist:

Don't stress yourself out, just answer the above to the best of your ability and we can discuss in the comments 🙂

tsale commented 1 year ago

Awesome, thanks for that @xC0uNt3r7hr34t! Is it possible to provide a screenshot of the various settings you can enable within the Sentinel platform just for tracking purposes?

xC0uNt3r7hr34t commented 1 year ago

Here is the telemetry config. note that named pipes are currently disabled by default and URL events require the browser extension to be deployed for full support. image