EDR Eligibility Criteria

Understanding which solutions qualify for comparison in the EDR Telemetry Project

Core Requirements

For an EDR solution to be included in our comparison, it must meet these basic requirements:

  • Provide real-time or near real-time event collection
  • Offer automated telemetry collection without manual intervention
  • Include out-of-the-box telemetry capabilities
  • Function as a dedicated endpoint detection and response solution

EDR Telemetry Definition

In this project, EDR Telemetry refers to data or events that are:

✓ Included

Automatically collected and transmitted by a sensor in real-time or near real-time as events occur

✗ Not Included

  • Historical events prior to EDR installation
  • Live querying of artifacts
  • Access to artifacts on a system
  • Signals or detections based on correlation
  • Additional modules or integrations

Solutions Not Currently Meeting Criteria

The following solutions are not included in our comparison as they don't currently meet one or more of the eligibility criteria:

Velociraptor Requires manual querying for artifact collection
OSquery (standalone) No automated real-time event collection
Huntress EDR Limited automated telemetry collection
Cisco EDR Requires additional modules for basic EDR functionality