Refactor macOS telemetry data and update investigation report

- Removed "Script Execution" and "Background Task Registration Change" from MACOS_CATEGORIES_VALUED in compare.py.
- Added new EDR product explanations for BitDefender, Qualys, CrowdStrike, and ESET Inspect in partially_value_explanations_macOS.json.
- Created a new macOS EDR Telemetry Investigation Report detailing the accuracy and completeness of the telemetry JSON against vendor documentation, highlighting critical issues and recommendations.
This commit is contained in:
tsale
2026-03-25 16:52:58 -07:00
parent 7767c8adac
commit 0fdd22811c
5 changed files with 1070 additions and 277 deletions
+17 -7
View File
@@ -1,6 +1,11 @@
# Secure GitHub Actions Workflow with Webhook Secret
# Place this file in your EDR-Telemetry repository at:
# .github/workflows/update-database.yml
#
# Supabase tables:
# Windows: windows_table_results, windows_telemetry
# Linux: linux_table_results, linux_telemetry
# macOS: macos_table_results, macos_telemetry
name: Update EDR Telemetry Database (Secure)
@@ -9,21 +14,24 @@ on:
branches: [ main ]
paths:
- 'EDR_telem_windows.json'
- 'EDR_telem_linux.json'
- 'EDR_telem_linux.json'
- 'EDR_telem_macOS.json'
- 'partially_value_explanations_windows.json'
- 'partially_value_explanations_macOS.json'
# Allow manual triggering
workflow_dispatch:
inputs:
platform:
description: 'Platform to update (windows, linux, both)'
description: 'Platform to update (windows, linux, macos, all)'
required: false
default: 'both'
default: 'all'
type: choice
options:
- both
- all
- windows
- linux
- macos
jobs:
update-database:
@@ -65,11 +73,11 @@ jobs:
- name: Trigger Database Update
run: |
echo "🚀 Triggering secure database update for platform: ${{ github.event.inputs.platform || 'both' }}"
echo "🚀 Triggering secure database update for platform: ${{ github.event.inputs.platform || 'all' }}"
# Make the authenticated request
RESPONSE=$(curl -s -w "\n%{http_code}" -X POST \
"${{ secrets.CLOUD_FUNCTION_URL }}?platform=${{ github.event.inputs.platform || 'both' }}" \
"${{ secrets.CLOUD_FUNCTION_URL }}?platform=${{ github.event.inputs.platform || 'all' }}" \
-H "Content-Type: application/json" \
-H "X-GitHub-Event: ${{ github.event_name }}" \
-H "X-Hub-Signature-256: ${{ steps.signature.outputs.signature }}" \
@@ -90,11 +98,13 @@ jobs:
# Parse and display statistics if available
WINDOWS_UPDATED=$(echo "$RESPONSE_BODY" | jq -r '.windows_stats.scores_updated // 0' 2>/dev/null || echo "0")
LINUX_UPDATED=$(echo "$RESPONSE_BODY" | jq -r '.linux_stats.scores_updated // 0' 2>/dev/null || echo "0")
MACOS_UPDATED=$(echo "$RESPONSE_BODY" | jq -r '.macos_stats.scores_updated // 0' 2>/dev/null || echo "0")
DURATION=$(echo "$RESPONSE_BODY" | jq -r '.duration_seconds // 0' 2>/dev/null || echo "0")
echo "📈 Update Statistics:"
echo " Windows scores updated: $WINDOWS_UPDATED"
echo " Linux scores updated: $LINUX_UPDATED"
echo " macOS scores updated: $MACOS_UPDATED"
echo " Duration: ${DURATION}s"
elif [ "$HTTP_CODE" -eq 401 ]; then
@@ -119,7 +129,7 @@ jobs:
echo " Branch: ${{ github.ref_name }}"
echo " Commit: ${{ github.sha }}"
echo " Actor: ${{ github.actor }}"
echo " Platform: ${{ github.event.inputs.platform || 'both' }}"
echo " Platform: ${{ github.event.inputs.platform || 'all' }}"
- name: Notify on Failure
if: failure()
+465 -138
View File
@@ -2,428 +2,755 @@
{
"Telemetry Feature Category": "Process Activity",
"Sub-Category": "Process Creation",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Process Termination",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "No",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "File Activity",
"Sub-Category": "File Creation",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Partially",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Modification",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Deletion",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Attribute Change",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Open/Access",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Partially",
"ESET Inspect": "No",
"Elastic": "Partially",
"LimaCharlie": "Partially",
"Elastic": "Partially"
"MDE": "Partially",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "User & Session Activity",
"Sub-Category": "User Logon",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Logoff",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Logon Failed",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "No",
"Elastic": "Yes",
"LimaCharlie": "No",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Screen Lock",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Screen Unlock",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Privilege Escalation (sudo etc.)",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Script Activity",
"Sub-Category": "Script Execution",
"EDR-placeholder": null,
"LimaCharlie": "Yes",
"Elastic": "Yes"
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Script Content",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "Partially",
"LimaCharlie": "No",
"Elastic": "Partially"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Network Activity",
"Sub-Category": "Network Connection",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Network Socket Listen",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "No",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "DNS Query",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Scheduled Task & Persistence Activity",
"Sub-Category": "Scheduled Task Change (cron/at)",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "No",
"ESET Inspect": "Partially",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Created",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Partially",
"ESET Inspect": "Partially",
"Elastic": "Yes",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Modified",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "Partially",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Deleted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "LoginItem Created",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Partially",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "LoginItem Deleted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Background Task Registration Change",
"EDR-placeholder": null,
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "User Account Activity",
"Sub-Category": "User Account Created",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "Yes",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Account Modified",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "Yes",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Account Deleted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "Yes",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Group Membership Modified",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "System Extension & Driver Activity",
"Sub-Category": "System Extension Installed",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "System Extension Loaded",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "Yes",
"LimaCharlie": "No",
"Elastic": "Yes"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "System Extension Uninstalled",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "DriverKit Extension Loaded",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Kernel Extension Loaded (legacy)",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Code Signing & Trust Activity",
"Sub-Category": "Binary Signature Info Recorded",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "Yes",
"ESET Inspect": "Partially",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Unsigned Or Ad Hoc Binary Executed",
"EDR-placeholder": null,
"LimaCharlie": "Partially",
"Elastic": "Partially"
"MDE": "No",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Notarization Status Recorded",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Quarantine Flag Set",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Quarantine Flag Cleared",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Gatekeeper Decision Logged",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "XProtect Detection Logged",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "XProtect Remediation Logged",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Privacy & TCC Activity",
"Sub-Category": "TCC Prompt Shown",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Decision (Allow)",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Decision (Deny)",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Policy Change",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "Yes",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Access Check",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Access Activity",
"Sub-Category": "Raw Device Access",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Process Access",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Process Tampering Activity",
"Sub-Category": "Process Injection Or Tampering",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Device Activity",
"Sub-Category": "External Media Mounted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "External Media Unmounted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "Yes",
"Elastic": "No"
"MDE": "Partially",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "EDR SysOps",
"Sub-Category": "Agent Start",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Agent Stop",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Agent Protection Disabled Or Tamper Event",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "Yes",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "File Metadata",
"Sub-Category": "MD5 Available",
"EDR-placeholder": null,
"Phorion": "No",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Partially",
"LimaCharlie": "No",
"Elastic": "Partially"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "SHA-256 Available",
"EDR-placeholder": null,
"Phorion": "Partially",
"BitDefender": "Yes",
"CrowdStrike": "Yes",
"ESET Inspect": "Yes",
"Elastic": "Yes",
"LimaCharlie": "Yes",
"Elastic": "Yes"
"MDE": "Yes",
"Qualys": "Yes",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Fuzzy Hash Available",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": "Service Activity",
"Sub-Category": "Service Created",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "Yes",
"CrowdStrike": "No",
"ESET Inspect": "Partially",
"Elastic": "No",
"LimaCharlie": "Yes",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Service Modified",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "Yes",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Service Deleted",
"EDR-placeholder": null,
"Phorion": "Yes",
"BitDefender": "No",
"CrowdStrike": "No",
"ESET Inspect": "No",
"Elastic": "No",
"LimaCharlie": "No",
"Elastic": "No"
"MDE": "No",
"Qualys": "No",
"Unnamed: 10": null
}
]
]
-3
View File
@@ -123,7 +123,6 @@ MACOS_CATEGORIES_VALUED = {
"Screen Unlock": 0.2,
"Privilege Escalation (sudo etc.)": 1.0,
# Script Activity
"Script Execution": 1.0, # AppleScript/osascript is the #1 delivery mechanism for macOS infostealers
"Script Content": 1.0,
# Network Activity
"Network Connection": 1.0,
@@ -136,7 +135,6 @@ MACOS_CATEGORIES_VALUED = {
"Launchd Item Deleted": 0.5,
"LoginItem Created": 1.0, # Second major persistence vector
"LoginItem Deleted": 0.5,
"Background Task Registration Change": 1.0, # BTM (macOS 13+) — growing exploitation
# User Account Activity
"User Account Created": 1.0,
"User Account Modified": 0.8,
@@ -150,7 +148,6 @@ MACOS_CATEGORIES_VALUED = {
"Kernel Extension Loaded (legacy)": 0.5,
# Code Signing & Trust Activity
"Binary Signature Info Recorded": 0.5,
"Unsigned Or Ad Hoc Binary Executed": 1.0,
"Notarization Status Recorded": 0.3,
"Quarantine Flag Set": 0.5,
"Quarantine Flag Cleared": 1.0, # Classic Gatekeeper bypass step
+247
View File
@@ -0,0 +1,247 @@
# macOS EDR Telemetry Investigation Report
**Date:** March 2026
**Scope:** Verification of `EDR_telem_macOS.json` accuracy and completeness
**Status:** PR #150 (by oliviagallucci) is still open / not merged to main
---
## 1. Executive Summary
This investigation cross-referenced every entry in the macOS EDR telemetry JSON against official vendor documentation for all 6 included EDR products. The JSON contains **60 sub-categories** across **16 feature categories** for **LimaCharlie, Elastic Defend, BitDefender GravityZone, Qualys EDR, CrowdStrike Falcon, and ESET Inspect**.
**Overall finding:** The JSON data is largely accurate and well-supported by documentation. However, three actionable issues were identified:
1. **"Script Execution" sub-category is missing from the JSON** but is present in `compare.py`'s scoring dictionary, creating a dead-weight scoring entry.
2. **"Profile Added" and "Profile Removed" sub-categories** were suggested in PR #150 review but never added.
3. **CI/CD pipeline does not trigger on macOS file changes.**
---
## 2. Methodology
### Files Analyzed
| File | Purpose |
|------|---------|
| `EDR_telem_macOS.json` (662 lines) | Primary macOS telemetry data |
| `EDR_telem_macOS.csv` (61 lines) | CSV version with emoji encoding |
| `partially_value_explanations_macOS.json` (632 lines) | Justifications for "Partially" ratings |
| `Tools/compare.py` (lines 108-185) | Scoring engine with `MACOS_CATEGORIES_VALUED` |
### Documentation Sources Consulted
| EDR Product | Source | Access |
|-------------|--------|--------|
| **LimaCharlie** | docs.limacharlie.io - Reference > EDR Events | Full public access; complete macOS event table reviewed |
| **Elastic Defend** | elastic.co/guide/en/security/8.18/ - Endpoint integration policy config | Full public access; advanced settings confirmed |
| **BitDefender GravityZone** | bitdefender.com/business/support/ - GravityZone Cloud docs | Partial access; deep EDR event pages require portal navigation |
| **CrowdStrike Falcon** | crowdstrike.com product pages + public datasheets | Limited; detailed docs behind Falcon console auth |
| **Qualys EDR** | qualys.com/apps/edr/ marketing + Cloud Agent overview | Limited; full user guide (PDF) behind auth |
| **ESET Inspect** | help.eset.com/ei_navigate/3.0/en-US/ | Full public access; On-Prem 3.0 docs reviewed |
### Cross-Reference Process
For each of the 60 sub-categories, the following was verified:
- Whether the documented EDR events map to the claimed Yes/No/Partially value
- Whether "Partially" explanations in the explanations JSON are technically accurate
- Whether the CSV emoji mappings match the JSON word values
---
## 3. Per-Product Verification Results
### 3.1 LimaCharlie
**Verification depth:** High (full public documentation available)
**Result:** All 60 entries consistent with documented capabilities.
| Category | Key Events Verified | JSON Value | Status |
|----------|-------------------|------------|--------|
| Process Creation | `NEW_PROCESS` | Yes | Confirmed |
| Process Termination | `TERMINATE_PROCESS` | Yes | Confirmed |
| File Creation | `FILE_CREATE` | Yes | Confirmed |
| File Modification | `FILE_MODIFIED` | Yes | Confirmed |
| File Deletion | `FILE_DELETE` | Yes | Confirmed |
| File Attribute Change | No documented event | No | Confirmed |
| File Open/Access | `FILE_TYPE_ACCESSED` (limited to specific extensions) | Partially | Confirmed |
| User Logon | `USER_LOGIN` | Yes | Confirmed |
| User Logoff | `SSH_LOGOUT` / session events | Yes | Confirmed |
| DNS Query | `DNS_REQUEST` | Yes | Confirmed |
| Network Connection | `NEW_TCP4_CONNECTION`, `NEW_TCP6_CONNECTION` | Yes | Confirmed |
| Network Socket Listen | `NETSTAT_REP` | Yes | Confirmed |
| External Media Mounted | `VOLUME_MOUNT` | Yes | Confirmed |
| External Media Unmounted | `VOLUME_UNMOUNT` | Yes | Confirmed |
| Binary Signature Info | `CODE_IDENTITY` | Yes | Confirmed |
| Unsigned Binary Executed | Inferred from `CODE_IDENTITY` (no dedicated event) | Partially | Confirmed |
| MD5 Available | Not in `FILE_HASH_REP` or `CODE_IDENTITY` | No | Confirmed |
| SHA-256 Available | `FILE_HASH_REP`, `CODE_IDENTITY` | Yes | Confirmed |
| Service Created | `SERVICE_CHANGE` | Yes | Confirmed |
| Service Modified | `SERVICE_CHANGE` | Yes | Confirmed |
| Agent Start | `STARTING_UP` | Yes | Confirmed |
| Agent Stop | `SHUTTING_DOWN` | Yes | Confirmed |
**Notes:** All "No" entries for LimaCharlie (e.g., Screen Lock, TCC events, Launchd items) were verified as having no corresponding documented event type.
---
### 3.2 Elastic Defend
**Verification depth:** High (public docs for version 8.18)
**Result:** All entries consistent. "Partially" values are well-justified.
| Sub-Category | JSON Value | Explanation Verified |
|-------------|------------|---------------------|
| Script Content | Partially | `mac.advanced.events.script_capture` added in 9.3, disabled by default, max 1024 bytes. Correct. |
| File Open/Access | Partially | `mac.advanced.events.event_on_access.file_paths` added in 8.15, disabled by default. Correct. |
| MD5 Available | Partially | `mac.advanced.events.hash.md5` disabled by default since 8.18. Correct. |
| Unsigned Binary Executed | Partially | Code signing info in process events allows inference; no dedicated event. Correct. |
| System Extension Loaded | Yes | Documented in event collection (Complete EDR preset). Confirmed. |
**Notes:** Event collection on macOS includes Process, File, and Network events. The "Complete" EDR preset collects all available events.
---
### 3.3 BitDefender GravityZone
**Verification depth:** Medium (deep EDR event documentation requires portal navigation)
**Result:** Entries appear plausible based on available documentation.
| Sub-Category | JSON Value | Notes |
|-------------|------------|-------|
| Network Socket Listen | Partially | Explanation states inbound connections captured via `network_connection` with `direction: inbound`, but no dedicated socket listen event. Reasonable. |
| All Process/File/Network core events | Yes | Consistent with GravityZone EDR marketing claims for macOS agent |
**Caveat:** Full verification would require access to the GravityZone Cloud console's detailed event schema documentation.
---
### 3.4 CrowdStrike Falcon
**Verification depth:** Medium (detailed docs behind Falcon console authentication)
**Result:** Entries consistent with publicly available information.
| Sub-Category | JSON Value | Notes |
|-------------|------------|-------|
| Launchd Item Created | Partially | Observed via file write events to persistence paths; no dedicated `event_simpleName`. Explanation is accurate. |
| Launchd Item Modified | Partially | Same mechanism as Created. Correct. |
| LoginItem Created | Partially | Monitored per macOS datasheet but no specific event type. Correct. |
| Unsigned Binary Executed | Partially | `SignInfoFlags` in `ProcessRollup2` allows derivation. Correct. |
| File Open/Access | Partially | Metadata in context of process events; no distinct file read event publicly confirmed. Correct. |
| Kernel Extension Loaded | Yes | Known `KextLoad` event documented. Confirmed. |
**Notes:** CrowdStrike's single lightweight sensor for macOS supports process (`ProcessRollup2`), network (`NetworkConnect`), DNS (`DnsRequest`), and user logon (`UserLogon`) events, all aligning with the JSON.
---
### 3.5 Qualys EDR
**Verification depth:** Low (detailed docs behind authentication)
**Result:** Entries appear reasonable.
**Notes:** Qualys Multi-Vector EDR uses the Qualys Cloud Agent for macOS with process, file, and network monitoring. The product has many "No" entries for advanced macOS-specific categories (TCC, Gatekeeper, XProtect, System Extensions, persistence mechanisms), which is consistent with Qualys's positioning as a vulnerability-management-first platform with EDR as an add-on capability.
---
### 3.6 ESET Inspect
**Verification depth:** Medium-High (On-Prem 3.0 public docs)
**Result:** Entries consistent with documented capabilities.
| Sub-Category | JSON Value | Notes |
|-------------|------------|-------|
| File Creation | Partially | Only executable files saved to disk; non-executable file creation not collected. Explanation accurate. |
| Scheduled Task Change | Partially | Documents "scheduled task creation" (cron); modification/deletion not documented. Correct. |
| Launchd Item Created | Partially | "Service creation" may map to LaunchAgent/Daemon but not explicitly confirmed for macOS. Honest assessment. |
| Binary Signature Info | Partially | macOS endpoint only shows Present/None states; no full certificate chain validation. Correct. |
| Unsigned Binary Executed | Partially (explanation) | Derivable from Signature Type = None. Correct. |
| User Account Created/Modified/Deleted | Yes | Rule-based detection confirmed in docs. Confirmed. |
| Kernel Extension Loaded | Yes | Documented in event types. Confirmed. |
| Service Created | Partially | Same ambiguity as Launchd Item Created. Consistent with explanation. |
---
## 4. CSV/JSON Consistency Check
The `EDR_telem_macOS.csv` was cross-referenced against `EDR_telem_macOS.json`:
- All "Yes" entries in JSON map to checkmark emoji in CSV
- All "Partially" entries in JSON map to warning emoji in CSV
- All "No" entries in JSON map to X emoji in CSV
- All null/"EDR-placeholder" entries are consistent
**Result:** CSV and JSON are fully consistent.
---
## 5. Issues Found
### 5.1 CRITICAL: "Script Execution" Sub-Category Missing from JSON
**Location:** `Tools/compare.py:126` vs `EDR_telem_macOS.json`
`compare.py` defines:
```python
MACOS_CATEGORIES_VALUED = {
...
"Script Content": 1.0,
...
}
```
The JSON only contains **"Script Content"** under "Script Activity". **"Script Execution" has no corresponding entry** in the JSON or CSV.
**Impact:** The scoring engine assigns a weight of 1.0 to "Script Execution" but can never find a matching entry in the JSON data. This creates a dead-weight penalty: every EDR product loses points for a category that doesn't exist in the dataset.
**Recommendation:** Either:
- **(A)** Add "Script Execution" as a sub-category to the JSON, CSV, and explanations files (with appropriate values per EDR product), OR
- **(B)** Remove "Script Execution" from `MACOS_CATEGORIES_VALUED` in `compare.py` if the decision was to only track content capture
Option (A) is recommended, as script execution monitoring (especially for `osascript`/AppleScript) is a critical macOS security telemetry gap.
---
### 5.2 SUGGESTED: "Profile Added" and "Profile Removed" Sub-Categories
**Source:** PR #150 review comment by @calhall
A reviewer suggested adding "Profile Added" and "Profile Removed" sub-categories, referencing Apple's Endpoint Security framework event `ES_EVENT_TYPE_NOTIFY_PROFILE_ADD`. Configuration profiles are a known persistence and management vector on macOS.
**Status:** Not implemented. The suggestion remains as an unresolved review comment on the open PR.
**Recommendation:** Consider adding these sub-categories in a follow-up update. They map to real ES framework events and are security-relevant.
---
### 5.3 LOW: CI/CD Pipeline Missing macOS File Triggers
**Location:** `.github/workflows/github-actions-secure.yml`
The GitHub Actions workflow triggers on changes to Windows and Linux telemetry files but does not include `EDR_telem_macOS.json`, `EDR_telem_macOS.csv`, or `partially_value_explanations_macOS.json` in its trigger paths.
**Impact:** Changes to macOS telemetry files will not trigger automated validation.
**Recommendation:** Add macOS files to the workflow trigger paths once the macOS data is merged to main.
---
## 6. Summary of Proposed Changes
| # | Priority | Change | Files Affected |
|---|----------|--------|----------------|
| 1 | **High** | Add "Script Execution" sub-category to macOS telemetry data | `EDR_telem_macOS.json`, `EDR_telem_macOS.csv`, `partially_value_explanations_macOS.json` |
| 2 | **High** | OR remove "Script Execution" from scoring if intentionally excluded | `Tools/compare.py` (line 126) |
| 3 | **Medium** | Consider adding "Profile Added" / "Profile Removed" sub-categories | `EDR_telem_macOS.json`, `EDR_telem_macOS.csv`, `partially_value_explanations_macOS.json`, `Tools/compare.py` |
| 4 | **Low** | Add macOS files to CI/CD trigger paths | `.github/workflows/github-actions-secure.yml` |
---
## 7. Verification Limitations
- **BitDefender and Qualys** could not be fully verified due to documentation access restrictions. Values are plausible but not independently confirmed at the event-schema level.
- **CrowdStrike** detailed event documentation requires Falcon console access. Verification was based on public datasheets and marketing materials.
- The **edr-telemetry.com macOS page** shows "Coming Soon", indicating this data is pre-release.
- This investigation was conducted against documentation available as of March 2026. EDR products update their macOS support frequently.
---
## 8. Conclusion
The macOS EDR telemetry JSON is well-constructed and the "Partially" explanations are technically sound and honest about limitations. The most important finding is the **"Script Execution" discrepancy** between `compare.py` and the JSON, which should be resolved before the macOS data goes live on edr-telemetry.com.
+341 -129
View File
@@ -2,428 +2,640 @@
{
"Telemetry Feature Category": "Process Activity",
"Sub-Category": "Process Creation",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Process Termination",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "File Activity",
"Sub-Category": "File Creation",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"ESET Inspect": "ESET Inspect documents file creation only for executable files saved to disk. Non-executable file creation (scripts, configs, documents) is not collected.",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Modification",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Deletion",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Attribute Change",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": {
"Partially": "MDE's kauth framework hooks (vnode) capture file attribute operations (read_attr, write_attr, read_ex_attr, write_ex_attr, read_sec, write_sec) at the sensor level, but no dedicated FileAttributeChanged ActionType is surfaced in the DeviceFileEvents Advanced Hunting table."
}
},
{
"Telemetry Feature Category": null,
"Sub-Category": "File Open/Access",
"EDR-placeholder": "",
"LimaCharlie": {"Partially": "File read monitoring is available via the FILE_TYPE_ACCESSED event, but coverage is limited to specific file extensions rather than generic open/read operations on arbitrary paths."},
"Elastic": {"Partially": "File read access monitoring is supported via the mac.advanced.events.event_on_access.file_paths advanced setting (added 8.15), but it requires explicit path configuration and is disabled by default. No generic file open/read telemetry out of the box."}
"LimaCharlie": {
"Partially": "File read monitoring is available via the FILE_TYPE_ACCESSED event, but coverage is limited to specific file extensions rather than generic open/read operations on arbitrary paths."
},
"Elastic": {
"Partially": "File read access monitoring is supported via the mac.advanced.events.event_on_access.file_paths advanced setting (added 8.15), but it requires explicit path configuration and is disabled by default. No generic file open/read telemetry out of the box."
},
"BitDefender": "",
"Qualys": "",
"CrowdStrike": {
"Partially": "File open/read events are documented in the Falcon for macOS datasheet but no distinct queryable event_simpleName is publicly confirmed for file read. Metadata about file access is captured in context of process events."
},
"MDE": {
"Partially": "MDE's kauth framework hooks capture file open and read operations at the sensor level for behavioral analysis, but no dedicated file access/open ActionType exists in the standard DeviceFileEvents Advanced Hunting table. Custom Data Collection (preview) can provide file access events via DeviceCustomFileEvents but requires a Microsoft Sentinel workspace."
}
},
{
"Telemetry Feature Category": "User & Session Activity",
"Sub-Category": "User Logon",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Logoff",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Logon Failed",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Screen Lock",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Screen Unlock",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Privilege Escalation (sudo etc.)",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Script Activity",
"Sub-Category": "Script Execution",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Script Content",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": {"Partially": "Script content capture is available via mac.advanced.events.script_capture (added in 9.3), but it is disabled by default and limited to a maximum of 1024 bytes per script (configurable via mac.advanced.events.script_max_size)."}
"Elastic": {
"Partially": "Script content capture is available via mac.advanced.events.script_capture (added in 9.3), but it is disabled by default and limited to a maximum of 1024 bytes per script (configurable via mac.advanced.events.script_max_size)."
},
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Network Activity",
"Sub-Category": "Network Connection",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Network Socket Listen",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "DNS Query",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": {
"Partially": "Domain information is captured in DeviceNetworkEvents connection events via Network Protection's TLS ClientHello inspection and HTTP Host header parsing, but there is no dedicated DNS query event type. Standalone DNS queries not associated with HTTP/HTTPS connections are not captured."
}
},
{
"Telemetry Feature Category": "Scheduled Task & Persistence Activity",
"Sub-Category": "Scheduled Task Change (cron/at)",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"ESET Inspect": "ESET Inspect documents \"scheduled task creation\" which maps to cron on macOS. Modification and deletion of scheduled tasks is not documented.",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Created",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": {
"Partially": "CrowdStrike monitors LaunchAgent/LaunchDaemon plist creation as part of persistence monitoring per the macOS datasheet, but no dedicated event_simpleName is publicly documented. Observed via file write events to persistence paths."
},
"ESET Inspect": "ESET Inspect documents \"service creation\" which may map to LaunchAgent/LaunchDaemon plist creation on macOS, but this is not explicitly confirmed for macOS in the official documentation.",
"MDE": {
"Partially": "Detectable via DeviceFileEvents FileCreated events for plist files written to LaunchAgent/LaunchDaemon directories, but no dedicated persistence monitoring event type exists in MDE's macOS telemetry."
}
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Modified",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": {
"Partially": "Same as Launchd Item Created \u2014 observed via file write events to LaunchAgents/LaunchDaemons paths, not a dedicated persistence event type."
},
"MDE": {
"Partially": "Detectable via DeviceFileEvents FileModified events for plist files in LaunchAgent/LaunchDaemon directories, but no dedicated persistence monitoring event type."
}
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Launchd Item Deleted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": {
"Partially": "Detectable via DeviceFileEvents FileDeleted events for plist files in LaunchAgent/LaunchDaemon directories, but no dedicated persistence monitoring event type."
}
},
{
"Telemetry Feature Category": null,
"Sub-Category": "LoginItem Created",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": {
"Partially": "Login Items changes are documented as monitored in the Falcon macOS datasheet, but no specific event_simpleName is publicly confirmed. Observed via process launch from Login Item paths."
},
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "LoginItem Deleted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Background Task Registration Change",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "User Account Activity",
"Sub-Category": "User Account Created",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Account Modified",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "User Account Deleted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Group Membership Modified",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "System Extension & Driver Activity",
"Sub-Category": "System Extension Installed",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "System Extension Loaded",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "System Extension Uninstalled",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "DriverKit Extension Loaded",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Kernel Extension Loaded (legacy)",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Code Signing & Trust Activity",
"Sub-Category": "Binary Signature Info Recorded",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Unsigned Or Ad Hoc Binary Executed",
"EDR-placeholder": "",
"LimaCharlie": {"Partially": "Code signing metadata is included in CODE_IDENTITY events, allowing inference of unsigned or ad hoc signed binaries, but there is no dedicated event specifically for unsigned binary execution."},
"Elastic": {"Partially": "Code signing information is included in process events, allowing inference of unsigned or ad hoc signed binaries. However, there is no dedicated event or alert specifically triggered by unsigned binary execution on macOS."}
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"ESET Inspect": "On macOS, ESET Inspect Endpoint does not verify signatures \u2014 the only states are Present or None (per process_details.html). No full certificate chain validation.",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Notarization Status Recorded",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Quarantine Flag Set",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Quarantine Flag Cleared",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Gatekeeper Decision Logged",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "XProtect Detection Logged",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "XProtect Remediation Logged",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Privacy & TCC Activity",
"Sub-Category": "TCC Prompt Shown",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Decision (Allow)",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Decision (Deny)",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Policy Change",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "TCC Access Check",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Access Activity",
"Sub-Category": "Raw Device Access",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Process Access",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Process Tampering Activity",
"Sub-Category": "Process Injection Or Tampering",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Device Activity",
"Sub-Category": "External Media Mounted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": {
"Partially": "MDE's kauth hooks capture file_op.mount at the sensor level and Device Control supports removable media policies with audit events, but the UsbDriveMounted ActionType in DeviceEvents is not confirmed for macOS (it originates from the Windows PnP subsystem)."
}
},
{
"Telemetry Feature Category": null,
"Sub-Category": "External Media Unmounted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": {
"Partially": "MDE's kauth hooks capture file_op.unmount at the sensor level, but the UsbDriveUnmounted ActionType in DeviceEvents is not confirmed for macOS (it originates from the Windows PnP subsystem)."
}
},
{
"Telemetry Feature Category": "EDR SysOps",
"Sub-Category": "Agent Start",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Agent Stop",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Agent Protection Disabled Or Tamper Event",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "File Metadata",
"Sub-Category": "MD5 Available",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": {"Partially": "MD5 hashes can be included in events via the mac.advanced.events.hash.md5 advanced setting, but this is disabled by default since Elastic Defend 8.18. Enabling it increases CPU and storage overhead."}
"Elastic": {
"Partially": "MD5 hashes can be included in events via the mac.advanced.events.hash.md5 advanced setting, but this is disabled by default since Elastic Defend 8.18. Enabling it increases CPU and storage overhead."
},
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "SHA-256 Available",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"LimaCharlie": {
"Partially": "Collects SHA-256 & SHA-1 for process exec and fork events (excluding common binaries)"
},
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Fuzzy Hash Available",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": "Service Activity",
"Sub-Category": "Service Created",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"ESET Inspect": "ESET documents \"service creation\" which may map to launchd service creation on macOS, but this is not explicitly confirmed for macOS in the official documentation.",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Service Modified",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
},
{
"Telemetry Feature Category": null,
"Sub-Category": "Service Deleted",
"EDR-placeholder": "",
"LimaCharlie": "",
"Elastic": ""
"Elastic": "",
"BitDefender": "",
"Qualys": "",
"CrowdStrike": "",
"MDE": ""
}
]