Core requirements
Included products must provide real-time event collection, automated telemetry without manual pulls, and out-of-the-box EDR capabilities as a dedicated endpoint sensor.
Rules that decide which products belong in the public telemetry comparison, and which stay out of scope.
Foundations
Terms used in the inclusion and exclusion rules below.
Included products must provide real-time event collection, automated telemetry without manual pulls, and out-of-the-box EDR capabilities as a dedicated endpoint sensor.
Data or events automatically collected and transmitted by a sensor as activity occurs. Live query, artifact access, and correlation-only signals do not qualify.
Products that lack continuous real-time streaming, require manual collection, or withhold raw telemetry from customer analysis stay out of scope.
Each scored event must capture a distinct system action directly. Inferring service creation from a generic process event is not full credit.
Scoring gate
A product must expose automatically collected telemetry that a customer can search, export, hunt on, or use for investigation. Live query, point-in-time artifact collection, historical backfill, manual collection, and backend-only conclusions do not qualify as scoring telemetry.
Telemetry should be available for customer search within ten minutes by default, unless an engagement defines a different window.
Telemetry must be reachable through the agreed product UI, API, or export without vendor engineering, support-only retrieval, or manual backend extraction.
Direct events count. Inferences from unrelated file, process, registry, or log activity do not receive full direct-event credit.
Directness
Each telemetry event must represent a distinct system action, captured directly rather than inferred.
Direct telemetry
A direct service-creation event exposed by the product through Windows Service Control Manager or an equivalent native sensor signal.
Insufficient substitute
Assuming service creation from a generic process event or a registry write under the Services key.
Out of scope
Search products and limitations. Exclusion means out of scope for this comparison, not that a product is weak.
Many listed products fit other use cases well. These criteria exist to compare traditional EDR telemetry capabilities, not to rank overall detection or prevention capabilities.
Next
Methodology covers validity, status values, and evidence expectations used after a product clears eligibility.