EDR-Telemetry
EDR-Telemetry copied to clipboard
Add more telemetry coverage for MDE on Windows
EDR Telemetry Pull Request
Contribution Details
Adding telemetry that is covered by MDE on Windows machines
Telemetry Validation
Documentation or Evidence:
- [ ] Official documentation (link: )
- [X] Screenshots attached
- [ ] Sanitized logs provided
- [ ] Private documentation (will share confidentially)
Type of Contribution
- [X] Adding telemetry information for an existing EDR product
- [ ] Adding a new EDR product that meets eligibility criteria
- [ ] Proposing new event categories/sub-categories
- [ ] Documentation improvement
- [ ] Tool enhancement
Validation Details
EDR Product Information
- EDR Product Name: Defender for Endpoint
- EDR Version: Engine: 1.1.25030.1, Service: 4.18.25030.2
- Operating System(s) Tested: Windows 11, 24H2
Testing Methodology
Running telemetry-generator.ps1 to generate
Additional Notes
- Service Creation
- Service Deletion
Not entirely sure how to classify this one. It's huntable, but it was within the DeviceRegistryEvents table:
- Virtual Disk Mount (iso)
- BITS Job
Doesn't appear to be huntable, other than via the DeviceProcessEvents table.