Skip to content

Commit

Permalink
Refactor SentinelOne field in EDR telemetry configuration to remove r…
Browse files Browse the repository at this point in the history
…edundancy
  • Loading branch information
tsale committed Dec 17, 2024
1 parent 0b0491a commit c51747d
Showing 1 changed file with 34 additions and 34 deletions.
68 changes: 34 additions & 34 deletions EDR_telem_linux.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
{
"Telemetry Feature Category":"Process Activity",
"Sub-Category":"Process Creation",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -16,7 +16,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Process Termination",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -30,7 +30,7 @@
{
"Telemetry Feature Category":"File Manipulation",
"Sub-Category":"File Creation",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -44,7 +44,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"File Modification",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -58,7 +58,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"File Deletion",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"No",
Expand All @@ -72,7 +72,7 @@
{
"Telemetry Feature Category":"User Activity",
"Sub-Category":"User Logon",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"Yes",
"CrowdStrike":"No",
Expand All @@ -86,7 +86,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"User Logoff",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"Yes",
"CrowdStrike":"No",
Expand All @@ -100,7 +100,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Logon Failed",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"Yes",
"CrowdStrike":"No",
Expand All @@ -114,7 +114,7 @@
{
"Telemetry Feature Category":"Script Activity",
"Sub-Category":"Script Content",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"Yes",
Expand All @@ -128,7 +128,7 @@
{
"Telemetry Feature Category":"Network Activity",
"Sub-Category":"Network Connection",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -142,7 +142,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Network Socket Listen",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"Partially",
"Uptycs":"No",
"CrowdStrike":"Yes",
Expand All @@ -156,7 +156,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"DNS Query",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Via EnablingTelemetry",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -170,7 +170,7 @@
{
"Telemetry Feature Category":"Scheduled Task Activity",
"Sub-Category":"Scheduled Task",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -184,7 +184,7 @@
{
"Telemetry Feature Category":"User Account Activity",
"Sub-Category":"User Account Created",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -198,7 +198,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"User Account Modified",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -212,7 +212,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"User Account Deleted",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -226,7 +226,7 @@
{
"Telemetry Feature Category":"Driver\/Module Activity",
"Sub-Category":"Driver Load",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -240,7 +240,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Image Load",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -254,9 +254,9 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"eBPF Event",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"Uptycs":"Via EnablingTelemetry",
"CrowdStrike":"Yes",
"Sysmon":"No",
"LimaCharlie":"No",
Expand All @@ -268,9 +268,9 @@
{
"Telemetry Feature Category":"Access Activity",
"Sub-Category":"Raw Access Read",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"Uptycs":"Via EnablingTelemetry",
"CrowdStrike":"No",
"Sysmon":"Yes",
"LimaCharlie":"No",
Expand All @@ -282,9 +282,9 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Process Access",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"Uptycs":"Via EnablingTelemetry",
"CrowdStrike":"No",
"Sysmon":"No",
"LimaCharlie":"No",
Expand All @@ -296,9 +296,9 @@
{
"Telemetry Feature Category":"Process Tampering Activity",
"Sub-Category":"Process Tampering",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"Uptycs":"Via EnablingTelemetry",
"CrowdStrike":"No",
"Sysmon":"No",
"LimaCharlie":"No",
Expand All @@ -310,7 +310,7 @@
{
"Telemetry Feature Category":"Service Activity",
"Sub-Category":"Service Creation",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -324,7 +324,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Service Modification",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -338,7 +338,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Service Deletion",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand All @@ -352,7 +352,7 @@
{
"Telemetry Feature Category":"EDR SysOps",
"Sub-Category":"Agent Start",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -366,7 +366,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"Agent Stop",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -380,7 +380,7 @@
{
"Telemetry Feature Category":"Hash Algorithms",
"Sub-Category":"MD5",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -394,7 +394,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"SHA",
"SentinelOne (Complete)":"Yes",
"SentinelOne":"Yes",
"Qualys":"Yes",
"Uptycs":"Yes",
"CrowdStrike":"Yes",
Expand All @@ -408,7 +408,7 @@
{
"Telemetry Feature Category":null,
"Sub-Category":"IMPHASH",
"SentinelOne (Complete)":"No",
"SentinelOne":"No",
"Qualys":"No",
"Uptycs":"No",
"CrowdStrike":"No",
Expand Down

0 comments on commit c51747d

Please sign in to comment.