# tsale/EDR-Telemetry

This project aims to compare and evaluate the telemetry of various EDR products.

Repository: https://github.com/tsale/EDR-Telemetry
Canonical: https://ross.abutalabs.com/products/edr-telemetry
Homepage: https://edr-telemetry.com
Language: Python
License: NOASSERTION
License Family: other
Last push: 2026-08-12T07:33:56+00:00

## Health v2 (maintenance only)
Score: 81/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 56, longevity 89
- inputs: {"age_days": 1250, "days_push": 21, "days_rel": 134, "gap_med": 147, "n_releases_24m": 2}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1978, forks 200 (observed 2026-08-28T04:06:01.558759+00:00)

## What it is
An open, vendor-neutral research project that compares the endpoint telemetry exposed by EDR products and agents like Sysmon across Windows, Linux, and macOS. It publishes a scored, evidence-backed comparison table plus a Python scoring script, maintained by Defendpoint Consulting.

## Use cases
- compare telemetry coverage of EDR products before buying one
- find visibility gaps in my current EDR deployment
- evaluate which endpoint events Sysmon vs commercial EDRs expose
- validate EDR telemetry during a proof of concept
- research endpoint event coverage for detection engineering
- check which EDRs expose scheduled task creation or registry events

## When to choose
- you need an independent, evidence-backed comparison of EDR telemetry visibility
- you are evaluating or validating EDR platforms across Windows, Linux, and macOS
- you want a public reference to push vendors toward telemetry transparency
- you are doing detection engineering or threat hunting research on endpoint event sources

## When to avoid
- you want a tool that ranks overall EDR protection, detection efficacy, or prevention quality
- you need a runnable telemetry collection agent rather than a comparison dataset
- you require a commercially licensed dataset for commercial use (CC BY-NC 4.0)
- you need real-time monitoring or alerting from the project itself

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, analytics, benchmarking
- domain: security, developer-tools, monitoring
- platform: windows, cross-platform
- tags: edr, telemetry, endpoint-security, detection-engineering, sysmon, vendor-comparison, threat-hunting, research, linux, macos

## Member repositories
- tsale/EDR-Telemetry (main) score 81

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:01.558759+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:04:45.628825+00:00, confidence not recorded.
  - readme: https://github.com/tsale/EDR-Telemetry (fetched 2026-08-28T04:06:01.558759+00:00, sha 466ba7d6d584)
  - homepage: https://edr-telemetry.com (fetched 2026-08-29T10:43:52.227633+00:00, sha d63061c5aaff)
  - site_page: https://www.edr-telemetry.com/about (fetched 2026-08-29T10:43:52.237181+00:00, sha 47a4ea91584c)
  - site_page: https://www.edr-telemetry.com/methodology (fetched 2026-08-29T10:43:52.239330+00:00, sha 170f2f3df7b8)
  - site_page: https://www.edr-telemetry.com/faq (fetched 2026-08-29T10:43:52.241289+00:00, sha 80991f071ff3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
