EDR Telemetry Scores
Compare the telemetry capabilities of different EDR solutions based on our transparent, weighted scoring methodology.
Loading scores...
Understanding the Scores
Our scoring system evaluates exposed telemetry visibility across categories. Each telemetry feature is weighted based on its importance for investigation, hunting, and response.
Scores reflect telemetry availability and exposed visibility. They do not measure prevention, detection efficacy, product quality, SOC maturity, managed service quality, or full incident-response capability. See the methodology page for the evidence standard.
Status Values
| Status | Value | Meaning |
|---|---|---|
| Yes | 1.0 | Required telemetry is implemented and exposed directly. |
| Via EnablingTelemetry | 1.0 | Available only after enabling a built-in setting or feature. Same numeric value as Yes, but not equivalent to out-of-the-box Yes. |
| Partially | 0.5 | Related telemetry exists, but full-credit validity fails because it is incomplete, conditional, subset-only, inconsistent, missing required fields, or related-but-not-direct. |
| Via EventLogs | 0.5 | Surfaced through platform-native OS logs rather than independent native sensor collection. |
| No | 0 | Telemetry is not implemented or is not exposed in a qualifying way. |
| Pending Response | 0 | Unresolved at scoring time. It cannot be upgraded without qualifying evidence. |
Feature Weights
Each telemetry feature category is weighted based on its importance in the overall assessment. Some key examples include:
Optional Telemetry & Fair Scoring
To maintain fair and consistent scoring across all EDR vendors, new Sub-Categories are initially marked as "optional" and do not count against the final scoring until they reach sufficient adoption across the vendor ecosystem.
New Sub-Categories only contribute to vendor scores once they achieve at least 75% implementation coverage across the supported vendor set for the scoped platform.
Only Yes and Via EnablingTelemetry count as implementation coverage. Partially, Via EventLogs, No, and Pending Response do not count toward the threshold unless a future methodology version changes the rule.
Optional telemetry features are marked with a New badge in the telemetry tables and will be promoted to scored telemetry once the coverage threshold is met.
Final Score Calculation
The final score represents the weighted sum of all non-optional features, providing a comprehensive evaluation of each EDR solution's telemetry capabilities.
To calculate the score:
- Optional telemetry features are excluded from the scoring calculation
- For each remaining telemetry feature (sub-category), we determine the implementation status (Yes, Partially, Via EventLogs, etc.)
- The status is converted to a numerical value according to the status table
- This value is multiplied by the weight assigned to that feature category
- All weighted values are summed to produce the final score
This methodology ensures that higher-weight telemetry capabilities have greater score impact while preserving evidence-backed status labels. See the full status taxonomy for directness and evidence rules.
