MISSION, SCOPE & GOVERNANCE

About the EDR Telemetry Project

We document which endpoint events EDR products expose under controlled, versioned tests.

  • Windows, Linux & macOS coverage
  • Published methodology & evidence standards
  • Independent, vendor-neutral research
Read the Methodology

Project overview

What This Project Is

Defendpoint Consulting maintains this as open research. We document and compare the endpoint telemetry EDR platforms expose under controlled, versioned tests.

Telemetry visibility

We test which endpoint events EDR platforms collect and expose for investigation, under documented conditions.

Built for practitioners

Use the results to compare visibility gaps, validate a deployment, or gather evidence for a platform choice. Scores cover exposed telemetry. They leave prevention quality, detection efficacy, and managed-service quality out of scope.

Results you can recheck

We publish what we tested, what evidence we saw, how we classified it, and which limits still apply.

Project Goals

  • Document EDR telemetry visibility using repeatable, evidence-backed testing
  • Compare telemetry coverage across supported platforms and products
  • Identify visibility gaps and implementation differences relevant to investigation and detection work
  • Give practitioners evidence they can use during EDR validation and evaluation
  • Encourage clearer vendor documentation and greater transparency around telemetry capabilities
  • Maintain explicit scope boundaries so telemetry scores are not confused with overall product quality

In scope

We measure telemetry visibility exposed to product consumers: raw or near-raw endpoint event data you can search or use for investigation, hunting, or detection engineering.

  • Endpoint activity automatically collected by the sensor
  • Events generated as activity occurs
  • Telemetry available in real time or near real time within the methodology's defined window
  • Data exposed through customer-accessible product interfaces, APIs, or export paths
  • Direct event records that meet the project's validity and evidence criteria

Out of scope

  • Prevention efficacy
  • Detection efficacy
  • Quality of built-in alerts or analytics
  • MDR or managed service quality
  • Overall incident response maturity
  • Overall product quality or “best EDR” ranking
  • Commercial value, licensing, or support quality as part of the telemetry score

How We Test

We design tests so each conclusion traces to a controlled action, the environment, the product evidence, and the methodology version used to classify the result.

1

Define scope and test conditions

Record operating system, product and sensor versions, configuration, enabled modules, and other conditions relevant to the result.

2

Execute controlled activity

Generate specific endpoint actions using repeatable tests and project tooling where available.

3

Collect raw or near-raw evidence

Review telemetry available to the product consumer rather than relying only on alerts, documentation, or vendor claims.

4

Map expected versus observed telemetry

Determine whether the event directly represents the action being tested and whether required fields or context are present.

5

Apply evidence and validity criteria

Assign status using the published methodology and document important caveats or missing evidence.

6

Publish scope and limitations

Keep product version, test conditions, evidence path, and known limitations visible so results can be rechecked.

See the Testing Methodology

Limits of use

Telemetry is one evaluation input. Pair it with detection quality, response capabilities, operational fit, integrations, staffing, infrastructure, licensing, compliance needs, vendor support, and other local factors.

  • Does not rank EDRs overall
  • Does not test prevention
  • Does not test detection efficacy
  • Does not evaluate MDR
  • Does not replace a client-specific proof of value
  • Does not guarantee identical telemetry across every deployment or product version

How the Project Relates to Defendpoint Consulting

The EDR Telemetry Project is maintained by Defendpoint Consulting and serves as a public research foundation for its EDR advisory and engineering work. The public project focuses on transparent telemetry research. Client-specific EDR selection, deployment, migration, validation, optimization, and advisory engagements are delivered separately through Defendpoint Consulting.

Public benchmark results remain subject to the project's published methodology and evidence standards. Client engagements may have additional scope, configuration, and decision criteria that are documented separately for the organization involved.

Explore Defendpoint EDR Services

Open and Community-Informed

The project is maintained by Defendpoint Consulting and improved through public feedback, technical contributions, vendor corrections, researcher review, and community participation. Community input helps identify gaps and improve accuracy, while published findings remain subject to the project's methodology and evidence standards.

Public Feedback

Researchers, practitioners, vendors, and users can report inaccuracies, provide evidence, suggest telemetry categories, and identify areas that need retesting.

Contributor and Supporter Community

The Discord community gives active contributors and project supporters a focused place to discuss findings, validation questions, research ideas, and project updates.

Get Involved

The project's research and methodology are publicly accessible. Discord access is available to active contributors and project supporters to keep the technical discussion focused and manageable.

Kostas

PROJECT MAINTAINER

Kostas

Kostas is an EDR researcher and security practitioner focused on endpoint telemetry, threat hunting, detection engineering, malware analysis, and incident response. He leads Defendpoint Consulting's EDR advisory and research work and maintains the EDR Telemetry Project, coordinating testing, evidence review, methodology development, and community contributions.

Get Involved or Get in Touch

Have evidence to contribute, a correction to report, or a question about the project? Use the project contact and contribution channels. For client-specific EDR selection, deployment, validation, or advisory work, contact Defendpoint Consulting directly.