Scope criteria

Eligibility and excluded products

Rules that decide which products belong in the public telemetry comparison, and which stay out of scope.

Foundations

Key definitions

Terms used in the inclusion and exclusion rules below.

Core requirements

Included products must provide real-time event collection, automated telemetry without manual pulls, and out-of-the-box EDR capabilities as a dedicated endpoint sensor.

EDR telemetry

Data or events automatically collected and transmitted by a sensor as activity occurs. Live query, artifact access, and correlation-only signals do not qualify.

Exclusion factors

Products that lack continuous real-time streaming, require manual collection, or withhold raw telemetry from customer analysis stay out of scope.

Direct vs inferred

Each scored event must capture a distinct system action directly. Inferring service creation from a generic process event is not full credit.

Scoring gate

Telemetry eligibility standard

A product must expose automatically collected telemetry that a customer can search, export, hunt on, or use for investigation. Live query, point-in-time artifact collection, historical backfill, manual collection, and backend-only conclusions do not qualify as scoring telemetry.

Near-real-time window

Telemetry should be available for customer search within ten minutes by default, unless an engagement defines a different window.

Consumer availability

Telemetry must be reachable through the agreed product UI, API, or export without vendor engineering, support-only retrieval, or manual backend extraction.

Directness requirement

Direct events count. Inferences from unrelated file, process, registry, or log activity do not receive full direct-event credit.

Read the full methodology criteria

Directness

Direct telemetry vs substitutes

Each telemetry event must represent a distinct system action, captured directly rather than inferred.

Direct telemetry

Counts for scoring

A direct service-creation event exposed by the product through Windows Service Control Manager or an equivalent native sensor signal.

Insufficient substitute

Does not count as direct

Assuming service creation from a generic process event or a registry write under the Services key.

Out of scope

Excluded products

Search products and limitations. Exclusion means out of scope for this comparison, not that a product is weak.

Scope note

Many listed products fit other use cases well. These criteria exist to compare traditional EDR telemetry capabilities, not to rank overall detection or prevention capabilities.

Product
Primary limitation
Additional details
Sandfly
No Real-time Streaming
  • Lacks continuous real-time telemetry streaming capabilities of traditional EDR solutions
  • Focuses on periodic scanning and threat hunting rather than continuous monitoring
  • Designed for point-in-time forensics and incident response rather than real-time detection
Velociraptor
Manual Collection Required
  • Relies on manual VQL queries for artifact collection
  • No continuous automated telemetry stream
  • Better suited for incident response than continuous monitoring
OSquery (standalone)
No Real-time Collection
  • Designed for point-in-time queries
  • Lacks native event streaming capability
  • Requires additional tooling for continuous monitoring
Huntress EDR
Limited EDR Functionality
  • Lacks direct access to raw telemetry data for customer analysis and investigation
  • Managed threat hunting platform rather than traditional EDR
  • Limited endpoint telemetry visibility for customers
Cisco EDR
Limited EDR Functionality
  • Lacks direct access to raw telemetry data for customer analysis and investigation
  • Requires additional modules and licensing for basic EDR capabilities
  • Limited endpoint telemetry visibility in base product
Tanium
Limited Real-Time Telemetry
  • Primarily focuses on forensic endpoint visibility rather than real-time telemetry ingestion
  • Uses polling-based architecture instead of continuous event streaming, leading to potential telemetry gaps
  • Lacks continuous real-time process creation, file modification, and script execution monitoring
Kaspersky
Limited Telemetry Access
  • Does not provide open access to detailed raw telemetry data
  • Telemetry data is aggregated, limiting granular event-level visibility
Aurora
Not a Full EDR Solution
  • Functions as a threat detection engine rather than a complete EDR solution
  • Relies on log ingestion and rule-based detection instead of real-time telemetry collection
  • Does not stream telemetry data to a centralized location for real-time analysis and monitoring
Wazuh
Different Product Category
  • Designed as a Unified XDR and SIEM platform with broader security monitoring scope beyond traditional EDR
  • While offering native telemetry capabilities, architecture differs from dedicated EDR sensor-based implementations
  • Platform focuses on unified security operations rather than specialized endpoint-centric EDR telemetry depth

Next

See how scoring applies these rules

Methodology covers validity, status values, and evidence expectations used after a product clears eligibility.

Open methodology