218 Commits

Author SHA1 Message Date
Kostas 47b5a98340 Uptycs macOS telemetry updates (#197)
* Update Uptycs macOS telemetry coverage

Consolidates Uptycs macOS telemetry updates from PRs #172-#179 into one OS-scoped change set.

* Update Uptycs macOS evidence statuses

---------

Co-authored-by: Hermes Agent <hermes-agent@users.noreply.github.com>
2026-05-17 13:54:36 -07:00
Kostas 4e92f79c2f C-Prot macOS telemetry updates (#195)
* Update C-Prot macOS telemetry coverage

Consolidates C-Prot macOS telemetry updates from PRs #182-#190 into one OS-scoped change set.

* fix: adjust C-Prot macOS telemetry statuses

Keep Raw Device Access accepted based on direct raw device access evidence, but leave Process Access and Process Injection Or Tampering as No because the submitted evidence is detection/prevention-oriented rather than direct telemetry.

---------

Co-authored-by: Hermes Agent <hermes-agent@users.noreply.github.com>
2026-05-14 11:22:06 -07:00
Bertrand Le Bail 3afe8902f5 Initial Coverage for Cortex XDR Agent on Linux (#148)
* Initial Coverage for Cortex XDR Agent on Linux

* Resolve Cortex XDR Linux telemetry conflicts

---------

Co-authored-by: tsale <kostastsale@gmail.com>
2026-05-13 16:12:25 -07:00
Colson Wilhoit 56de511ddc Update Elastic Defend macOS telemetry — 6 corrections (#167)
* Update Elastic Defend macOS telemetry — 6 corrections

3 items from Partially → Via EnablingTelemetry (policy toggle required):
- File Open/Access: mac.advanced.events.event_on_access.file_paths (8.15.0)
- Script Content: mac.advanced.events.script_capture (9.3.0)
- MD5 Available: mac.advanced.events.hash.md5 (8.16.0)

3 items from No → Yes (collected by default via ESF events):
- Quarantine Flag Cleared: event.action "extended_attributes_delete"
- Process Injection Or Tampering: event.action "remote_thread"
- Agent Protection Disabled Or Tamper Event: tamper protection (8.11.0+)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Remove unsupported Elastic telemetry scores on macOS

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Kostas <kostastsale@gmail.com>
2026-04-28 00:43:39 -07:00
Kostas 316e328502 Trigger database updater verification run 2026-04-28 00:05:07 -07:00
Kostas fa229135a9 Trigger database update workflow for updater changes 2026-04-27 23:50:17 -07:00
Kostas 7a27eb7faa Harden database update success checks 2026-04-27 23:44:48 -07:00
Kostas 053bb72199 Add C-Prot Windows and macOS telemetry results (#180)
* Refactor code structure for improved readability and maintainability

* Fix CSV-JSON status translation in convert.py

* Correcting Agent Protection Disabled
2026-04-27 23:23:44 -07:00
tsale abf07a8325 Fix Atomic Red Team path resolution in telemetry generator v0.3 2026-04-21 17:58:52 -07:00
Kostas 63ce215c68 Merge pull request #150 from oliviagallucci:oliviagallucci-macos-edr-telem
macOS EDR Categories and Sub Categories
2026-03-25 22:19:58 -07:00
tsale 83aa106dc7 Add Linux support to EDR Telemetry Cloud Function and update dependencies
- Include 'partially_value_explanations_linux.json' in GitHub Actions workflow triggers.
- Update .gitignore to include .env.yaml.
- Remove outdated macOS telemetry investigation report.
- Add example environment configuration file for Cloud Function.
- Implement deployment script for EDR Telemetry Updater Cloud Function.
- Create main function for handling webhook triggers and updating Supabase database.
- Update requirements.txt to include additional dependencies for Supabase client.
2026-03-25 22:05:53 -07:00
Kostas 6ff355716a Merge branch 'main' into oliviagallucci-macos-edr-telem 2026-03-25 17:07:26 -07:00
tsale 0fdd22811c Refactor macOS telemetry data and update investigation report
- Removed "Script Execution" and "Background Task Registration Change" from MACOS_CATEGORIES_VALUED in compare.py.
- Added new EDR product explanations for BitDefender, Qualys, CrowdStrike, and ESET Inspect in partially_value_explanations_macOS.json.
- Created a new macOS EDR Telemetry Investigation Report detailing the accuracy and completeness of the telemetry JSON against vendor documentation, highlighting critical issues and recommendations.
2026-03-25 16:52:58 -07:00
Josh Lemon b1965910b7 Update EDR_telem_linux.json - Uptycs - User Account (#165) 2026-03-23 18:22:06 -07:00
Josh Lemon 495ba50dd4 Grammer Update for "BITS Jobs" (#164) 2026-03-23 18:21:11 -07:00
Josh Lemon 5491d2509a Update EDR_telem_windows.json - Uptycs BIT Jobs (#163) 2026-03-23 18:20:30 -07:00
Josh Lemon a4cc2fecaf Update EDR_telem_linux.json - Uptycs - Image Load (#162) 2026-03-23 18:18:35 -07:00
Hüsnü Öner 19d8660a0b C-Prot Linux Script Activity (#161)
* Update EDR_telem_linux.json

Updated Linux Service Modification

* Update EDR_telem_linux.json

Updated C-Prot User Account Management

* Update EDR_telem_linux.json

C-Prot Linux Driver Load

* Update EDR_telem_linux.json

C-Prot Linux Script Activity
2026-03-23 18:16:55 -07:00
Hüsnü Öner edfdf64a9b C-Prot Linux Driver Module Activity (#160)
* Update EDR_telem_linux.json

Updated Linux Service Modification

* Update EDR_telem_linux.json

Updated C-Prot User Account Management

* Update EDR_telem_linux.json

C-Prot Linux Driver Load

* Fix missing newline at end of EDR_telem_linux.json

---------

Co-authored-by: Kostas <kostastsale@gmail.com>
2026-03-23 18:14:50 -07:00
Hüsnü Öner 6c57dbfcb8 C-Prot Linux User Account Management (#159)
* Update EDR_telem_linux.json

Updated Linux Service Modification

* Update EDR_telem_linux.json

Updated C-Prot User Account Management

* Fix missing newline at end of EDR_telem_linux.json

---------

Co-authored-by: Kostas <kostastsale@gmail.com>
2026-03-23 18:12:39 -07:00
Hüsnü Öner f7cf810ef5 Update EDR_telem_linux.json (#158)
Updated Linux Service Modification
2026-03-23 18:09:08 -07:00
Ján Trenčanský b3e969ea89 ESET USB Mount/Unmount (#157)
* ESET USB events+file open

* Update ESET Inspect telemetry description for sensitive file tracking

---------

Co-authored-by: Kostas <kostastsale@gmail.com>
2026-03-23 18:07:46 -07:00
Josh Lemon c65a1fb3f9 Update EDR_telem_windows.json - Agent Install + Keep Alive (#156) 2026-03-23 18:00:44 -07:00
Josh Lemon 69c640ef6d Update EDR_telem_windows.json - Uptycs Scheduled Task (#155) 2026-03-23 17:59:48 -07:00
Bertrand Le Bail 4e8e9d9fcb mass updates to Cortex XDR - Windows coverage (#146)
* mass updates to Cortex XDR - Windows coverage

* Update Cortex XDR telemetry status for device control and named pipe events

Change Virtual Disk Mount, USB Device Unmount, and USB Device Mount from Yes to Partially (requires Device Control in block mode). Change Volume Shadow Copy Deletion and Pipe Connection from Yes to No.

* Update Cortex XDR status in telemetry categories

---------

Co-authored-by: tsale <kostastsale@gmail.com>
2026-03-23 17:58:45 -07:00
tsale 7767c8adac Add Elastic scoring details to macOS telemetry feature categories 2026-03-14 12:44:56 -07:00
tsale 4897cf567e Add LimaCharlie scoring to macOS telemetry feature categories and remove profile activity scoring 2026-03-14 12:35:42 -07:00
tsale d94cff0e70 Enhance macOS-specific telemetry categories with detailed scoring for process, file, user, and network activities 2026-03-14 12:29:21 -07:00
tsale efd7831983 Update macOS telemetry generator documentation and implementation details
- Update MACOS_TELEMETRY_GENERATOR_GUIDE.md to reflect OpenDirectory.framework usage for UserAccountEvents instead of direct dslocal plist writes
- Clarify kext load/unload expectations on modern hardened macOS systems
- Revise CodeSignTrust description to focus on signature/trust enrichment validation via trusted vs tampered sample execution
- Update ProcessAccess to document task_for_pid as primary mechanism
- Add recommended
2026-02-12 13:21:08 -08:00
tsale 0e4e30e29c Changed the implementation of the disk image mount/unmount for external media telemetry generation
- Replace volume listing with hdiutil-based disk image creation, mounting, and unmounting
2026-01-27 22:48:26 -08:00
tsale 456b90e8c0 Add macOS support to EDR telemetry comparison tool
- Add MACOS_CATEGORIES_VALUED dictionary with macOS-specific telemetry categories
- Update determine_categories() to detect macOS files and return appropriate category set
- Update display_results() to show "macOS" OS type for macOS input files
- Simplify generate_scores() scoring logic by removing redundant try-except block
2026-01-27 17:22:32 -08:00
tsale 2b6e0830f9 Fix conversion script to preserve category columns and headers
- Skip replacements in "Telemetry Feature Category" and "Sub-Category" columns when converting CSV→JSON
- Skip header row and first two columns when converting JSON→CSV
- Refactor replace functions to use proper JSON parsing and line-by-line CSV processing
2026-01-25 20:23:27 -08:00
Kostas dcc5c175ea Added macOS telemetry generator tool and documentation. 2026-01-24 00:08:09 -08:00
tsale 5f1cbffc45 Update GitHub Actions workflow to auto-detect platform changes and add MITRE ATT&CK mappings trigger
- Add mitre_att&ck_mappings.json and partially_value_explanations_linux.json to workflow triggers
- Implement platform detection logic to determine if changes affect Windows, Linux, or both based on modified files
- Refactor database update calls to handle platform-specific updates separately when only one platform is affected
- Update workflow to use detected platform instead of manual input for
2026-01-20 12:52:18 -08:00
Josh Lemon e1974900ed Update EDR_telem_windows.json - Uptycs Win API Telemetry (#154) 2026-01-19 16:53:09 -08:00
Josh Lemon 5bf3cd98ba Update EDR_telem_linux.json - Uptycs Fuzzy Hash Telemetry (#153) 2026-01-19 16:52:00 -08:00
Thibault Boog e9f4b16dbb Update SentinelOne Linux eBPF telemetry status (#152) 2026-01-19 16:50:14 -08:00
oliviagallucci fab45330d8 removed space and File Open/Access events 2026-01-10 15:53:41 -05:00
oliviagallucci 16ee444881 Added TCC access check 2026-01-10 15:47:58 -05:00
oliviagallucci 3964f6cf73 test push 2026-01-10 15:40:42 -05:00
Kostas dcc73514c5 Add C-Prot telemetry coverage to Linux EDR telemetry matrix (#151) 2025-12-28 11:58:24 -08:00
oliviagallucci 0e333e5c27 telemetry area ideas 2025-12-16 17:47:35 -05:00
oliviagallucci 20eaaf2f5f removed all non null values 2025-12-16 15:26:39 -05:00
oliviagallucci a9841b6348 basic files 2025-12-16 15:14:50 -05:00
oliviagallucci 3aa7200654 base file copied from linux. nulls set 2025-12-16 10:59:10 -05:00
Josh Lemon a552fbc765 Update EDR_telem_linux.json - Uptycs Driver Load Telemetry via finit_module (#145) 2025-11-29 11:00:42 -08:00
Josh Lemon e026452b67 Update Uptycs Crontab in Linux Telemetry (#144) 2025-11-29 10:58:07 -08:00
Josh Lemon 537e92f735 Update Uptycs to include listening port telemetry (#143) 2025-11-29 10:55:41 -08:00
Yousef Helmy f7f722cece IMPHASH Correction (#142) 2025-11-29 10:53:50 -08:00
Jonathan Devere-Ellery 37245d0ef6 Updates for MDE on Windows and Linux (#140)
* Updates for MDE on Windows and Linux

* Update MDE Linux service telemetry status from Partially to No and remove explanation

---------

Co-authored-by: tsale <kostastsale@gmail.com>
2025-11-29 10:52:20 -08:00