...the missing layer.
Full write-up: www.edr-telemetry.com/blog/Why-You...
@kostastsale.bsky.social
Running โก http://defendpoint.ca | http://edr-telemetry.com | https://edr-comparison.com/ | http://detectionstream.com | ๐ฌ๐ท๐จ๐ฆ
...the missing layer.
Full write-up: www.edr-telemetry.com/blog/Why-You...
At EDR Telemetry project, we spend a lot of time measuring what EDRs can see. This article is about what they still cannot safely stop.
From LOLBAS to vulnerable drivers to unauthorized RMMs, I walk through the real-world gaps we keep seeing in telemetry and why application control is...
In the screenshot below, you can see an example of this Skill in use (I'm using GPT 5.2-low in Codex)
Link to the skill: github.com/tsale/awesom...
We have added a new analysis Skill thanks to @BlueTeamSteve! This skill can be used to quickly and accurately map the MITRE ATT&CK tactic and technique to threat behaviors and indicators you enter in the prompt, saving you a ton of time!
08.01.2026 18:16 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Weโve also expanded ๐๐ป๐๐ฒ๐ฟ๐ฝ๐ฟ๐ถ๐๐ฒ options for organizations that need additional flexibility, scale, and support on top of the Advanced tier.
Check out the new tiers now: www.edr-comparison.com/pricing
๐ช๐ฎ๐๐ฐ๐ต๐๐๐ฎ๐ฟ๐ฑ ๐๐๐ฅ. Weโve also introduced ๐๐ฎ๐๐ถ๐ฐ ๐ฎ๐ป๐ฑ ๐๐ฑ๐๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐ถ๐ฒ๐ฟ๐ to better reflect how different users engage with the platform. With the ๐๐ฑ๐๐ฎ๐ป๐ฐ๐ฒ๐ฑ ๐๐ถ๐ฒ๐ฟ, weโre introducing a deep dive into the technical justification and expert analysis behind every single feature in our comparison.
07.01.2026 17:02 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Since launching in November, the platform has already helped hundreds of consultants and enterprises navigate the complexity of EDR selection.
This release pushes things forward with a cleaner comparison UX, deeper evaluation context using MITRE ATT&CK evaluation data, and a new vendor added:
๐๐๐ฅ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐ฃ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ: ๐ก๐ฒ๐ ๐๐ป๐๐ฒ๐ฟ๐ฎ๐ฐ๐๐ถ๐๐ฒ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐๐
๐ฝ๐ฒ๐ฟ๐ถ๐ฒ๐ป๐ฐ๐ฒ, ๐ ๐๐ง๐ฅ๐ ๐๐ง๐ง&๐๐ ๐๐ป๐๐ถ๐ด๐ต๐๐, ๐ฎ๐ป๐ฑ ๐ช๐ฎ๐๐ฐ๐ต๐๐๐ฎ๐ฟ๐ฑ ๐๐๐ฅ
We want to start by thanking everyone who supported us as early adopters.
Feel free to contribute and use these skills to save a ton of time, like we already do.
github.com/tsale/awesom...
Learn about skills:
- developers.openai.com/codex/skills/
- support.claude.com/en/articles/...
๐๐๐๐ ๐น๐ฎ๐๐ป๐ฐ๐ต๐ฒ๐ฑ ๐ฎ๐๐ฒ๐๐ผ๐บ๐ฒ-๐ฑ๐ณ๐ถ๐ฟ-๐๐ธ๐ถ๐น๐น๐ ๐๐ถ๐๐ต @fr0gger_ !
Designed to save time during investigations and everyday DFIR tasks
Thomas has built an excellent malware triage skill, and Iโve added a couple of timeline analysis skills to help you get started.
github.com/tsale/EDR-Te...
This is exactly the kind of vendor collaboration the project aims to promote.
PR with full details and artifacts:
github.com/tsale/EDR-Te...
Big thanks to the C-Prot team for setting a strong example for Linux EDR transparency.
environment, validated event mappings, and publishedย the raw logs from the evaluation so the community can independently verify everything.
Artifacts included:
โข Real production telemetry logs
โข Some screenshots from the platform
Validation material to reproduce the results can be found under
Weโve just added ๐-๐ฃ๐ฟ๐ผ๐ EDR to the EDR Telemetry Project and it sets a new bar for Linux telemetry!
C-Prot is currently #1 in the Linux EDR table, with exceptional depth and quality of raw telemetry. What really stands out is the level of transparency: we got direct access to a production...
Be careful what you install and avoid using skills from unknown or unverified libraries.
Read more about skills here:
- support.claude.com/en/articles/...
- developers.openai.com/codex/skills/
One quick caveat tho, as skills libraries become more popular, where you will be able to search and find the right skill you want to install, weโre likely going to see malicious skills pop up that download and execute malware...
27.12.2025 00:18 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Claude set a strong bar for structured, workflow-driven AI usage, and itโs no surprise weโre now seeing similar ideas across other platforms like OpenAI.
Iโve built DFIR and quick triage workflows that save me hours every time! The time savings really add up, and itโs completely changed how I work.
Pretty ๐
25.12.2025 21:22 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Merry Christmas everyone! Hope everyoneโs enjoying some downtime ๐
25.12.2025 19:26 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Much of it remains applicable today, along with the threat hunting series, which Iโm especially proud of.
23.12.2025 17:10 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Iโve moved all of my blog posts from Medium to a new blog section on my personal website.
If youโre looking for a good read, Iโd recommend my Cobalt Strike write-ups (Part 1 & Part 2) from 2021โ2022.
kostas.page/blog/cobalt-...
Don't be naive. They will get rid of you at the first opportunity they find.
18.12.2025 22:22 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Many large companies are using AI and forcing their employees to use their AI models. They do this to train their AI models, getting them ready to replace many low-level analyst positions.
If you are a security analyst in one of these big organizations, you need to have plan Bโฆ.
Haha thank you, man! Appreciate you. Jokes aside, having passion and doing what you love is a big motivator. Helping people is also another one. At the end, we all come out winners.
16.12.2025 21:16 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Ah, dammit! I think that might be an issue with the mobile version of the website. I'll check it out and fix it. Thank you very much! I guess this adds an element of challenge for signing up ๐
Regarding your question, it's easy, I don't sleep ๐
The waitlist will close once a certain number of people have signed up and may reopen later if more testers are needed.
This is something I wish existed when I was starting in the industry, and something I still want today.
Register now, and more details soon.
threathuntinglabs.com
โข Work directly in ๐๐น๐ฎ๐๐๐ถ๐ฐ, ๐ฆ๐ฝ๐น๐๐ป๐ธ, ๐ผ๐ฟ ๐๐๐๐ฟ๐ฒ ๐๐ฎ๐๐ฎ ๐๐
๐ฝ๐น๐ผ๐ฟ๐ฒ๐ฟ and learn to investigate and huntย using hypotheses.
๐ง๐ต๐ฒ ๐๐ฎ๐ถ๐๐น๐ถ๐๐ ๐ถ๐ ๐ป๐ผ๐ ๐ผ๐ฝ๐ฒ๐ป!!
Those who sign up will receive a founders discount, early beta access, and the opportunity to provide feedback during development.
actually work, not another set of CTF-like labs or check-the-box exercises.
โข ๐๐ต๐ผ๐ผ๐๐ฒ ๐๐ผ๐๐ฟ ๐ผ๐๐ป ๐ถ๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐ ๐ถ๐ป๐๐ฒ๐๐๐ถ๐ด๐ฎ๐๐ถ๐ผ๐ป ๐ฝ๐ฎ๐๐ต: your choices determine how the investigation unfolds.
โข ๐ก๐ผ ๐บ๐ผ๐ฟ๐ฒ ๐ธ๐ฒ๐๐๐ผ๐ฟ๐ฑ ๐บ๐ฎ๐๐ฐ๐ต๐ถ๐ป๐ด. Answers are evaluated on intent and accuracy.
๐ข ๐โ๐บ ๐ฎ๐ป๐ป๐ผ๐๐ป๐ฐ๐ถ๐ป๐ด ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ ๐๐๐ป๐๐ถ๐ป๐ด ๐๐ฎ๐ฏ๐, ๐น๐ฎ๐๐ป๐ฐ๐ต๐ถ๐ป๐ด ๐ป๐ฒ๐
๐ ๐๐ฒ๐ฎ๐ฟ!
After building threat hunting teams for large MSSPs, creating DFIR Labs for TheDFIRReport, and sharing years of free threat hunting material, I want to bring everything together into one platform. Something closer to how investigations...
However, those improvements still need to be interpreted in context, and understanding the access used during evaluation for additional context.
This post explains what changed and why: www.edr-telemetry.com/blog/Behind-...