Community-powered evidence

How to Contribute

Submit telemetry updates, evidence, and docs that keep the comparison accurate. Follow the paths below, then open a GitHub PR.

Contribution Paths

Choose a path: telemetry data, validated evidence, or community issues

About ContributionsValidation Process

Telemetry updates

We welcome all kinds of contributions to the EDR_telem.json file. Use our tools to make contributing easier.

  • Convert between JSON and CSV formats
  • Edit in your preferred format
  • Automatic validation checks

Evidence Requirements

Status changes need recheckable evidence. Screenshots help. Disputed direct-test conclusions need the full evidence package.

Accepted evidence

Official vendor documentation
Screenshots of telemetry exposed by the product
Log extracts or raw event records
Direct hands-on testing results
Private documentation shared confidentially for validation

Direct-test checklist

Test/action executed and UTC execution timestamp
Endpoint, OS build, sensor version, and policy/configuration
Expected telemetry target and status being requested
Query/search used, time window, raw event source, table, or index
Observed fields, missing expected fields, screenshot or raw export
Rationale for Yes, Partially, Via EventLogs, Via EnablingTelemetry, No, or Pending Response

For No or absence findings

Document the search window, sources searched, queries or search terms, covered time range, endpoint identifiers examined, and any relevant vendor table or index guidance. Vague claims are not enough to upgrade or downgrade a status.

Contribution Steps

Fork, branch, update statuses with evidence, then open a pull request

Fork Repository

Create your own copy of the project.

  1. Visit the main repository
  2. Click the "Fork" button
  3. Select your account

Create Branch

Make a new branch for your changes.

git checkout -b feature-branch-name

Make Changes

Update telemetry values using the project status vocabulary.

Submit PR

Open a pull request with documentation and evidence.

  • Push your changes
  • Open pull request
  • Add documentation
  • Wait for review

Additional Guidelines

Keep issues and feature requests clear, current, and easy to act on

Reporting Issues

  • Check existing issues
  • Use latest version
  • Clear descriptions
  • Reproduction steps

Feature Requests

  • Check existing proposals
  • Clear title
  • Detailed description
  • Use case examples

Contribution FAQ

Quick answers drawn from the contribution and evidence guidance above

Official vendor documentation, screenshots of telemetry exposed by the product, log extracts or raw event records, direct hands-on testing results, and private documentation shared confidentially for validation.
Private documentation can be shared confidentially with Kostas. Status changes still need evidence that can be rechecked.
Include the test/action and UTC timestamp, endpoint and sensor details, expected telemetry target, query/search and time window, observed or missing fields with a screenshot or raw export, and a clear rationale for the requested status.
Document the search window, sources searched, queries or search terms, covered time range, endpoint identifiers examined, and any relevant vendor table or index guidance. Vague claims are not enough to upgrade or downgrade a status.

Contribute on GitHub

Small, well-evidenced PRs still matter. Open an issue first if the change needs discussion.