This is super cool and useful thanks for shareing. One thing that would be a possible awesome contribution would be to know the isolation capabilties of these tools? ie. can you remotely isolate affected systems? Understood this list is more related to the telemtry output from the different tools but it would be cool to know some other capabilities the tools have and be able to benchmark them. Also another step could be to include the DFIR capabilties of the tools but understand this would need significant reserach and testing. Just throwing ideas out there. Great project thanks again!
Thank you for the kind words. This project is focusing on the telemetry and not further Response capabilities/features of each EDR. Maybe that's a good idea for a different project.
This is super cool and useful thanks for shareing. One thing that would be a possible awesome contribution would be to know the isolation capabilties of these tools? ie. can you remotely isolate affected systems? Understood this list is more related to the telemtry output from the different tools but it would be cool to know some other capabilities the tools have and be able to benchmark them. Also another step could be to include the DFIR capabilties of the tools but understand this would need significant reserach and testing. Just throwing ideas out there. Great project thanks again!