tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.52k stars 147 forks source link

Fixing CrowdStrike's WMI Filter and Consumer Values #41

Closed tsale closed 10 months ago

tsale commented 10 months ago

Pull Request Template

Description

Documentation and evidence provided by a contributor suggesting that CrowdStrike includes telemetry for WMI Event Filter + WMI Event Consumer fields.

  1. Does the proposed EDR feature align with our definition of telemetry?(definition here)
  2. Could you please provide documentation to support the telemetry you are proposing?(If it is held privately, please reach out to me or @inodee)
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

1: Yes\ 2: Yes\ 3: Yes

Type of change

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.