tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.52k stars 147 forks source link

Add Cortex XDR based on public documentation #47

Closed pep-un closed 7 months ago

pep-un commented 8 months ago

The documentation used is on Corted XDR Pro on 2024-01-15

Pull Request Template

Description

Please provide the below information so we can validate before merging:

  1. Does the proposed EDR feature align with our definition of telemetry?(definition here)
  2. Could you please provide documentation to support the telemetry you are proposing?(If it is held privately, please reach out to me or @inodee)
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

1: Yes \ 2: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection \ 3: N/A

Type of change

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.

Test Configuration:

Checklist:

Don't stress yourself out, just answer the above to the best of your ability and we can discuss in the comments 🙂

tsale commented 8 months ago

Thanks very much for this submission @pep-un! I'll be reviewing this over the next couple of days and let you know if I have any questions! 🙏

Sam0x90 commented 7 months ago

After discussion with @tsale, here attached is a quick update based on public documentation. Happy to discuss and help on this case. xdr_telemetry.txt