56de511ddc Update Elastic Defend macOS telemetry — 6 corrections (#167)
* Update Elastic Defend macOS telemetry — 6 corrections

3 items from Partially → Via EnablingTelemetry (policy toggle required):
- File Open/Access: mac.advanced.events.event_on_access.file_paths (8.15.0)
- Script Content: mac.advanced.events.script_capture (9.3.0)
- MD5 Available: mac.advanced.events.hash.md5 (8.16.0)

3 items from No → Yes (collected by default via ESF events):
- Quarantine Flag Cleared: event.action "extended_attributes_delete"
- Process Injection Or Tampering: event.action "remote_thread"
- Agent Protection Disabled Or Tamper Event: tamper protection (8.11.0+)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Remove unsupported Elastic telemetry scores on macOS

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Kostas <kostastsale@gmail.com>
2026-04-28 00:43:39 -07:00
2025-04-11 10:26:26 -07:00

EDR Telemetry

EDR Telemetry Logo

Website FAQ License: CC BY-NC 4.0 Stars

📖 About

A comprehensive comparison of telemetry features from EDR products and endpoint agents like Sysmon. This project enables security practitioners to evaluate telemetry capabilities while promoting vendor transparency.

🌐 Visit our Website for the complete comparison and analysis.

📝 Read more about this project in our initial release blog post.

🎯 Key Features

  • Comprehensive telemetry comparison across multiple EDR solutions
  • Detailed scoring system for feature evaluation
  • Regular updates to reflect the latest capabilities
  • Community-driven contributions and verification

📊 Telemetry Comparison

Visit our EDR Telemetry Comparison Table to see:

  • Feature-by-feature comparison
  • Detailed scoring metrics
  • Implementation status
  • Latest updates

🤝 Contributing

We welcome contributions! Please check our Contribution Guidelines for details on how to get involved.

⚖️ Scoring System

Our evaluation script assigns scores based on feature implementation:

  • ✅ Yes: 1.0
  • ⚠️ Partially: 0.5
  • 🎚️ Via EnablingTelemetry: 1.0
  • 🪵 Via EventLogs: 0.5
  • ❌ No: 0.0
  • ❓ Pending Response: 0.0

View the complete scoring breakdown on our website.

⚠️ Disclaimer

The data presented reflects only the telemetry capabilities of each product, not their detection or prevention capabilities. For more details, please visit our FAQ page.

📜 License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

This means you are free to:

  • Share — copy and redistribute the material in any medium or format
  • Adapt — remix, transform, and build upon the material

Under the following terms:

  • Attribution — You must give appropriate credit, provide a link to the license, and indicate if changes were made.
  • NonCommercial — You may not use the material for commercial purposes without explicit permission from the author.

For commercial use, please contact us.

✨ Contributors Wall

Thanks to these amazing contributors:

Current Primary Maintainers

Kostas - @kostastsale

S
Description
Automated archival mirror of github.com/tsale/EDR-Telemetry
Readme
2.2 MiB
Languages
Python 89.7%
C# 5.1%
PowerShell 3.8%
Shell 1.4%