Kostas's Avatar

Kostas

@kostastsale.bsky.social

Running โžก http://defendpoint.ca | http://edr-telemetry.com | https://edr-comparison.com/ | http://detectionstream.com | ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡จ๐Ÿ‡ฆ

1,393 Followers  |  127 Following  |  441 Posts  |  Joined: 19.09.2023  |  2.1519

Latest posts by kostastsale.bsky.social on Bluesky

Preview
Why Your EDR Needs a Partner: The Case for Application Control How threat intelligence-aware application control fills the gaps that EDR leaves open

...the missing layer.

Full write-up: www.edr-telemetry.com/blog/Why-You...

13.01.2026 20:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why Your EDR Needs a Partner: The Case for Application Control How threat intelligence-aware application control fills the gaps that EDR leaves open

At EDR Telemetry project, we spend a lot of time measuring what EDRs can see. This article is about what they still cannot safely stop.

From LOLBAS to vulnerable drivers to unauthorized RMMs, I walk through the real-world gaps we keep seeing in telemetry and why application control is...

13.01.2026 20:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

In the screenshot below, you can see an example of this Skill in use (I'm using GPT 5.2-low in Codex)

Link to the skill: github.com/tsale/awesom...

08.01.2026 18:16 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

We have added a new analysis Skill thanks to @BlueTeamSteve! This skill can be used to quickly and accurately map the MITRE ATT&CK tactic and technique to threat behaviors and indicators you enter in the prompt, saving you a ton of time!

08.01.2026 18:16 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

Weโ€™ve also expanded ๐—˜๐—ป๐˜๐—ฒ๐—ฟ๐—ฝ๐—ฟ๐—ถ๐˜€๐—ฒ options for organizations that need additional flexibility, scale, and support on top of the Advanced tier.

Check out the new tiers now: www.edr-comparison.com/pricing

07.01.2026 17:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

๐—ช๐—ฎ๐˜๐—ฐ๐—ต๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—˜๐——๐—ฅ. Weโ€™ve also introduced ๐—•๐—ฎ๐˜€๐—ถ๐—ฐ ๐—ฎ๐—ป๐—ฑ ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐˜๐—ถ๐—ฒ๐—ฟ๐˜€ to better reflect how different users engage with the platform. With the ๐—”๐—ฑ๐˜ƒ๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐˜๐—ถ๐—ฒ๐—ฟ, weโ€™re introducing a deep dive into the technical justification and expert analysis behind every single feature in our comparison.

07.01.2026 17:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Since launching in November, the platform has already helped hundreds of consultants and enterprises navigate the complexity of EDR selection.

This release pushes things forward with a cleaner comparison UX, deeper evaluation context using MITRE ATT&CK evaluation data, and a new vendor added:

07.01.2026 17:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
EDR Comparison - Compare Endpoint Detection & Response Solutions Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

๐—˜๐——๐—ฅ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—ฃ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ: ๐—ก๐—ฒ๐˜„ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—˜๐˜…๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ, ๐— ๐—œ๐—ง๐—ฅ๐—˜ ๐—”๐—ง๐—ง&๐—–๐—ž ๐—œ๐—ป๐˜€๐—ถ๐—ด๐—ต๐˜๐˜€, ๐—ฎ๐—ป๐—ฑ ๐—ช๐—ฎ๐˜๐—ฐ๐—ต๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—˜๐——๐—ฅ

We want to start by thanking everyone who supported us as early adopters.

07.01.2026 17:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners. A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills

Feel free to contribute and use these skills to save a ton of time, like we already do.

github.com/tsale/awesom...

Learn about skills:
- developers.openai.com/codex/skills/
- support.claude.com/en/articles/...

30.12.2025 21:10 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners. A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills

๐—๐˜‚๐˜€๐˜ ๐—น๐—ฎ๐˜‚๐—ป๐—ฐ๐—ต๐—ฒ๐—ฑ ๐—ฎ๐˜„๐—ฒ๐˜€๐—ผ๐—บ๐—ฒ-๐—ฑ๐—ณ๐—ถ๐—ฟ-๐˜€๐—ธ๐—ถ๐—น๐—น๐˜€ ๐˜„๐—ถ๐˜๐—ต @fr0gger_ !

Designed to save time during investigations and everyday DFIR tasks

Thomas has built an excellent malware triage skill, and Iโ€™ve added a couple of timeline analysis skills to help you get started.

30.12.2025 21:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

github.com/tsale/EDR-Te...

This is exactly the kind of vendor collaboration the project aims to promote.
PR with full details and artifacts:

github.com/tsale/EDR-Te...

Big thanks to the C-Prot team for setting a strong example for Linux EDR transparency.

29.12.2025 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

environment, validated event mappings, and publishedย the raw logs from the evaluation so the community can independently verify everything.

Artifacts included:

โ€ข Real production telemetry logs
โ€ข Some screenshots from the platform

Validation material to reproduce the results can be found under

29.12.2025 15:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Add C-Prot telemetry coverage to Linux EDR telemetry matrix by tsale ยท Pull Request #151 ยท tsale/EDR-Telemetry EDR Telemetry Pull Request Contribution Details Adding comprehensive Linux telemetry support for C-Prot EDR, including detailed event mappings, field explanations, and validation artifacts. This co...

Weโ€™ve just added ๐—–-๐—ฃ๐—ฟ๐—ผ๐˜ EDR to the EDR Telemetry Project and it sets a new bar for Linux telemetry!

C-Prot is currently #1 in the Linux EDR table, with exceptional depth and quality of raw telemetry. What really stands out is the level of transparency: we got direct access to a production...

29.12.2025 15:00 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
What are Skills? | Claude Help Center Skills are available as a feature preview for users on Pro, Max, Team, and Enterprise plans. This feature preview requires code execution to be enabled. Skills are also available in beta for Claudeโ€ฆ

Be careful what you install and avoid using skills from unknown or unverified libraries.

Read more about skills here:
- support.claude.com/en/articles/...
- developers.openai.com/codex/skills/

27.12.2025 00:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
What are Skills? | Claude Help Center Skills are available as a feature preview for users on Pro, Max, Team, and Enterprise plans. This feature preview requires code execution to be enabled. Skills are also available in beta for Claudeโ€ฆ

One quick caveat tho, as skills libraries become more popular, where you will be able to search and find the right skill you want to install, weโ€™re likely going to see malicious skills pop up that download and execute malware...

27.12.2025 00:18 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Agent Skills Give Codex new capabilities and expertise

Claude set a strong bar for structured, workflow-driven AI usage, and itโ€™s no surprise weโ€™re now seeing similar ideas across other platforms like OpenAI.

Iโ€™ve built DFIR and quick triage workflows that save me hours every time! The time savings really add up, and itโ€™s completely changed how I work.

27.12.2025 00:18 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

Pretty ๐Ÿ˜

25.12.2025 21:22 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Merry Christmas everyone! Hope everyoneโ€™s enjoying some downtime ๐ŸŽ„

25.12.2025 19:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Much of it remains applicable today, along with the threat hunting series, which Iโ€™m especially proud of.

23.12.2025 17:10 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cobalt Strike, a Defender's Guide - Part 2 The second part of the Cobalt Strike defender's guide, focusing on network traffic analysis and practical detection methods to identify Cobalt Strike beacons in your environment.

Iโ€™ve moved all of my blog posts from Medium to a new blog section on my personal website.

If youโ€™re looking for a good read, Iโ€™d recommend my Cobalt Strike write-ups (Part 1 & Part 2) from 2021โ€“2022.

kostas.page/blog/cobalt-...

23.12.2025 17:06 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image 20.12.2025 16:40 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Don't be naive. They will get rid of you at the first opportunity they find.

18.12.2025 22:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Many large companies are using AI and forcing their employees to use their AI models. They do this to train their AI models, getting them ready to replace many low-level analyst positions.

If you are a security analyst in one of these big organizations, you need to have plan Bโ€ฆ.

18.12.2025 22:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Haha thank you, man! Appreciate you. Jokes aside, having passion and doing what you love is a big motivator. Helping people is also another one. At the end, we all come out winners.

16.12.2025 21:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Ah, dammit! I think that might be an issue with the mobile version of the website. I'll check it out and fix it. Thank you very much! I guess this adds an element of challenge for signing up ๐Ÿ˜‚

Regarding your question, it's easy, I don't sleep ๐Ÿ˜‚

16.12.2025 18:22 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
ThreatHunting Labs | Real Intrusion Training Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.

The waitlist will close once a certain number of people have signed up and may reopen later if more testers are needed.

This is something I wish existed when I was starting in the industry, and something I still want today.

Register now, and more details soon.

threathuntinglabs.com

16.12.2025 17:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ThreatHunting Labs | Real Intrusion Training Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.


โ€ข Work directly in ๐—˜๐—น๐—ฎ๐˜€๐˜๐—ถ๐—ฐ, ๐—ฆ๐—ฝ๐—น๐˜‚๐—ป๐—ธ, ๐—ผ๐—ฟ ๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐——๐—ฎ๐˜๐—ฎ ๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ฟ๐—ฒ๐—ฟ and learn to investigate and huntย using hypotheses.

๐—ง๐—ต๐—ฒ ๐˜„๐—ฎ๐—ถ๐˜๐—น๐—ถ๐˜€๐˜ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐—ผ๐—ฝ๐—ฒ๐—ป!!

Those who sign up will receive a founders discount, early beta access, and the opportunity to provide feedback during development.

16.12.2025 17:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
ThreatHunting Labs | Real Intrusion Training Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.

actually work, not another set of CTF-like labs or check-the-box exercises.

โ€ข ๐—–๐—ต๐—ผ๐—ผ๐˜€๐—ฒ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ผ๐˜„๐—ป ๐—ถ๐—ป๐—ฐ๐—ถ๐—ฑ๐—ฒ๐—ป๐˜ ๐—ถ๐—ป๐˜ƒ๐—ฒ๐˜€๐˜๐—ถ๐—ด๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฝ๐—ฎ๐˜๐—ต: your choices determine how the investigation unfolds.
โ€ข ๐—ก๐—ผ ๐—บ๐—ผ๐—ฟ๐—ฒ ๐—ธ๐—ฒ๐˜†๐˜„๐—ผ๐—ฟ๐—ฑ ๐—บ๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด. Answers are evaluated on intent and accuracy.

16.12.2025 17:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
ThreatHunting Labs | Real Intrusion Training Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.

๐Ÿ“ข ๐—œโ€™๐—บ ๐—ฎ๐—ป๐—ป๐—ผ๐˜‚๐—ป๐—ฐ๐—ถ๐—ป๐—ด ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—›๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ๐—Ÿ๐—ฎ๐—ฏ๐˜€, ๐—น๐—ฎ๐˜‚๐—ป๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—ป๐—ฒ๐˜…๐˜ ๐˜†๐—ฒ๐—ฎ๐—ฟ!

After building threat hunting teams for large MSSPs, creating DFIR Labs for TheDFIRReport, and sharing years of free threat hunting material, I want to bring everything together into one platform. Something closer to how investigations...

16.12.2025 17:38 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
Behind the Curtain: How the EDR Telemetry Project Approaches Vendor Relations, Evaluations, and Transparency Introducing transparency indicators and explaining how we validate telemetry while staying independent.

However, those improvements still need to be interpreted in context, and understanding the access used during evaluation for additional context.

This post explains what changed and why: www.edr-telemetry.com/blog/Behind-...

15.12.2025 13:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@kostastsale is following 20 prominent accounts