tsale / EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.
1.7k stars 158 forks source link

Update EDR_telem.json #48

Closed Robert-HarfangLab closed 8 months ago

Robert-HarfangLab commented 9 months ago

Pull Request Template

Description

Please provide the below information so we can validate before merging:

  1. Does the proposed EDR feature align with our definition of telemetry?(definition here)
  2. Could you please provide documentation to support the telemetry you are proposing?(If it is held privately, please reach out to me or @inodee)
  3. If no documentation is available for all the categories you are proposing, could you provide screenshots or sanitized logs?

1: Yes 2: Private 3: Screenshot in private

Type of change

Please delete options that are not relevant.

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration.

Use a VM to generate the right telemetry.

Test Configuration:

Checklist:

tsale commented 8 months ago

Thank you very much for the PR @Robert-HarfangLab! Could you confirm if the Telemetry Data Explorer contains raw telemetry data, based on the screenshots you sent me privately?

I just want to confirm before I go ahead and merge. Thanks!

Robert-HarfangLab commented 8 months ago

Hi, yes, it's indeed used for this you can go ahead and merge :)