Kostas
@kostastsale.bsky.social
Running โก http://defendpoint.ca | http://edr-telemetry.com | https://edr-comparison.com/ | http://detectionstream.com | ๐ฌ๐ท๐จ๐ฆ
๐ข๐ macOS is now part of the EDR Telemetry Project. After three months of focused work, weโre excited to share a new framework and generator for endpoint visibility on macOS! Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next.
macOS EDR Telemetry: A Structured Framework for Evaluating Endpoint Visibility.
EDR Telemetry Project - Exploring telemetry capabilities of EDR solutions
edr-telemetry.com
Itโs been quiet on the EDR Telemetry side lately while working on something big! EDR telemetry's goal was always to set the standard for telemetry visibility, and this is what we're planning to do with tomorrow's release... Keep an eye out for tomorrow's announcement!
Sometimes the call comes a little too late and you gotta do what you gotta do ๐
Phantom Stealer has been prominent across phishing campaigns over the past two weeks. Operationally interesting to me is that itโs not just an infostealer. It also acts as an initial access broker, dropping GuLoader for follow-on activity, and Iโve seen it deploy crypto miners as well.
Clinejection PoC: researcher proved you can compromise a VS Code extension (700k+ weekly users) via prompt injection in GitHub issues. He was kind enough to install harmless software as a POC. Real attackers won't... Vendor ignored him for 47 days, fixed it in 30 min after he went public.
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw
### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...
github.com
MDX content is awesome, I love it, and I use it whenever I can on my projects. But be careful cause if youโre usingย next-mdx-remoteย (4.3.0โ5.x) to serverโside render untrusted MDX, youโre potentially exposing yourself to RCE via CVEโ2026โ0969...
HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content
Bulletin ID: HCSEC-2026-01 Affected Products / Versions: next-mdx-remote from 4.3.0 up to 5.0.0, fixed in 6.0.0. Publication Date: February 11, 2026 Summary The serialize function used to compileโฆ
discuss.hashicorp.com
At EDR Telemetry project, we spend a lot of time measuring what EDRs can see. This article is about what they still cannot safely stop. From LOLBAS to vulnerable drivers to unauthorized RMMs, I walk through the real-world gaps we keep seeing in telemetry and why application control is...
Why Your EDR Needs a Partner: The Case for Application Control
How threat intelligence-aware application control fills the gaps that EDR leaves open
edr-telemetry.com
We have added a new analysis Skill thanks to @BlueTeamSteve! This skill can be used to quickly and accurately map the MITRE ATT&CK tactic and technique to threat behaviors and indicators you enter in the prompt, saving you a ton of time!
github.com
๐๐๐ฅ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐ฃ๐น๐ฎ๐๐ณ๐ผ๐ฟ๐บ ๐จ๐ฝ๐ฑ๐ฎ๐๐ฒ: ๐ก๐ฒ๐ ๐๐ป๐๐ฒ๐ฟ๐ฎ๐ฐ๐๐ถ๐๐ฒ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐๐ ๐ฝ๐ฒ๐ฟ๐ถ๐ฒ๐ป๐ฐ๐ฒ, ๐ ๐๐ง๐ฅ๐ ๐๐ง๐ง&๐๐ ๐๐ป๐๐ถ๐ด๐ต๐๐, ๐ฎ๐ป๐ฑ ๐ช๐ฎ๐๐ฐ๐ต๐๐๐ฎ๐ฟ๐ฑ ๐๐๐ฅ We want to start by thanking everyone who supported us as early adopters.
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
๐๐๐๐ ๐น๐ฎ๐๐ป๐ฐ๐ต๐ฒ๐ฑ ๐ฎ๐๐ฒ๐๐ผ๐บ๐ฒ-๐ฑ๐ณ๐ถ๐ฟ-๐๐ธ๐ถ๐น๐น๐ ๐๐ถ๐๐ต @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and Iโve added a couple of timeline analysis skills to help you get started.
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners.
A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills
github.com
Weโve just added ๐-๐ฃ๐ฟ๐ผ๐ EDR to the EDR Telemetry Project and it sets a new bar for Linux telemetry! C-Prot is currently #1 in the Linux EDR table, with exceptional depth and quality of raw telemetry. What really stands out is the level of transparency: we got direct access to a production...
Add C-Prot telemetry coverage to Linux EDR telemetry matrix by tsale ยท Pull Request #151 ยท tsale/EDR-Telemetry
EDR Telemetry Pull Request Contribution Details Adding comprehensive Linux telemetry support for C-Prot EDR, including detailed event mappings, field explanations, and validation artifacts. This co...
github.com
Claude set a strong bar for structured, workflow-driven AI usage, and itโs no surprise weโre now seeing similar ideas across other platforms like OpenAI. Iโve built DFIR and quick triage workflows that save me hours every time! The time savings really add up, and itโs completely changed how I work.
Agent Skills
Give Codex new capabilities and expertise
developers.openai.com
Merry Christmas everyone! Hope everyoneโs enjoying some downtime ๐
Iโve moved all of my blog posts from Medium to a new blog section on my personal website. If youโre looking for a good read, Iโd recommend my Cobalt Strike write-ups (Part 1 & Part 2) from 2021โ2022. kostas.page/blog/cobalt-...
Cobalt Strike, a Defender's Guide - Part 2
The second part of the Cobalt Strike defender's guide, focusing on network traffic analysis and practical detection methods to identify Cobalt Strike beacons in your environment.
kostas.page
Many large companies are using AI and forcing their employees to use their AI models. They do this to train their AI models, getting them ready to replace many low-level analyst positions. If you are a security analyst in one of these big organizations, you need to have plan Bโฆ.
๐ข ๐โ๐บ ๐ฎ๐ป๐ป๐ผ๐๐ป๐ฐ๐ถ๐ป๐ด ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ ๐๐๐ป๐๐ถ๐ป๐ด ๐๐ฎ๐ฏ๐, ๐น๐ฎ๐๐ป๐ฐ๐ต๐ถ๐ป๐ด ๐ป๐ฒ๐ ๐ ๐๐ฒ๐ฎ๐ฟ! After building threat hunting teams for large MSSPs, creating DFIR Labs for TheDFIRReport, and sharing years of free threat hunting material, I want to bring everything together into one platform. Something closer to how investigations...
ThreatHunting Labs | Real Intrusion Training
Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.
threathuntinglabs.com
๐๐ป๐๐ฟ๐ผ๐ฑ๐๐ฐ๐ถ๐ป๐ด: ๐ง๐ฟ๐ฎ๐ป๐๐ฝ๐ฎ๐ฟ๐ฒ๐ป๐ฐ๐ ๐๐ป๐ฑ๐ถ๐ฐ๐ฎ๐๐ผ๐ฟ๐ ๐ถ๐ป ๐๐ต๐ฒ ๐๐๐ฅ-๐ง๐ฒ๐น๐ฒ๐บ๐ฒ๐๐ฟ๐ ๐ฃ๐ฟ๐ผ๐ท๐ฒ๐ฐ๐! Transparency has always been central to the EDR Telemetry Project. Evaluations may involve different levels of access, and making that visible adds helpful context for readers.
Behind the Curtain: How the EDR Telemetry Project Approaches Vendor Relations, Evaluations, and Transparency
Introducing transparency indicators and explaining how we validate telemetry while staying independent.
edr-telemetry.com
โWeโve added ๐๐ถ๐๐ฐ๐ผ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ป๐ฑ๐ฝ๐ผ๐ถ๐ป๐ to the EDR-Comparison.com platform!! Cisco shows strength in prevention, indicator alerting, and response automation, with solid investigation visuals and well-documented APIs that integrate easily into broader security stacks. Itโs a platform that leans more...
As we are are approaching our goal, starting January, weโre updating the pricing for the ๐๐๐ฅ ๐๐ฒ๐ฎ๐๐๐ฟ๐ฒ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ. The platform has grown far beyond the initial dataset, and the new pricing reflects the depth of work going into the next phase of the project. ๐ช๐ต๐ฎ๐โ๐ ๐ฐ๐ผ๐บ๐ถ๐ป๐ด ๐ป๐ฒ๐ ๐:
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
Iโve been getting a lot of questions lately about the difference between the ๐๐๐ฅ ๐ง๐ฒ๐น๐ฒ๐บ๐ฒ๐๐ฟ๐ ๐ฃ๐ฟ๐ผ๐ท๐ฒ๐ฐ๐ and the ๐๐๐ฅ ๐๐ผ๐บ๐ฝ๐ฎ๐ฟ๐ถ๐๐ผ๐ป ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ. Theyโre related, but they solve completely different problems. Telemetry ๐ถ๐ ๐ผ๐ป๐ฒ ๐ฝ๐ถ๐ฒ๐ฐ๐ฒ ๐ผ๐ณ ๐๐ต๐ฒ ๐ฝ๐๐๐๐น๐ฒ. The comparison service ๐น๐ผ๐ผ๐ธ๐ ๐ฎ๐ ๐๐ต๐ฒ ๐ฒ๐ป๐๐ถ๐ฟ๐ฒ ๐๐ผ๐น๐๐๐ถ๐ผ๐ป.
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
This report from Bleeping is crazy, is You can't make this stuff up! ๐ www.bleepingcomputer.com/news/securit...
Quick update. We just added a new EDR vendor directory page to the platform. If you want a clean overview of whoโs included and a preview of the comparison features, start here: www.edr-comparison.com/directory
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
Heads-up on CVE-2025-55182: a CVSS 10.0 pre-auth RCE affecting React Server Components 19.x. Can be triggered through malicious HTTP payloads, so there will be chaos when a POC comes out. On that note...there are many fake POCs circulating. Be careful what you run. A POC is not available yet.
๐จ๐๐ถ๐ด ๐ฑ๐ฎ๐ ๐ณ๐ผ๐ฟ ๐๐ฒ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป๐ฆ๐๐ฟ๐ฒ๐ฎ๐บ. ๐ข๐ป๐ฒ ๐ผ๐ณ ๐ผ๐๐ฟ ๐น๐ฎ๐ฟ๐ด๐ฒ๐๐ ๐ฟ๐ฒ๐น๐ฒ๐ฎ๐๐ฒ๐ ๐๐ฒ๐. The platform now supports official pySigma validation fully in-browser, compiled to WebAssembly. Same validation as sigma-cli. Thanks to @sifex from detection.studio for the inspiration behind the implementation. Hereโs what we added:๐
A lot of folks have been asking how we run our EDR testing and what the methodology looks like behind the scenes. I put together a full deep dive walking through our process, the tooling we use, and how we score everything based on direct telemetry.
A Deep Dive into the EDR Telemetry Project's Direct Testing Methodology
How we test EDR products with hands-on execution, raw telemetry collection, and evidence-based scoring.
edr-telemetry.com
If youโre trying to use Wazuh for threat hunting or incident response, stop wasting your time. Wazuh is fine for compliance and system visibility, but thatโs where it ends.
๐ฅ๐ผ๐ฎ๐ฑ๐บ๐ฎ๐ฝ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ: the first milestone is done. The Interactive Comparison Interface now has its core engine in place. Good progress for week one, and more updates are coming along with more EDR vendors!
I just finished a big update for the EDR Telemetry website. Weโre preparing for many exciting updates and want to make sure weโre ready ๐ Check it out and let me know what you think - www.edr-telemetry.com
EDR Telemetry Project: Transparent Benchmarking & Telemetry Analysis for Businesses
Explore transparent, vendor-neutral EDR telemetry benchmarks. Make confident security decisions with real-world data and practical analysis for your business.
edr-telemetry.com
I'm reviving Teletracker. Missed working on it and it deserved a second life. I'm rt is way more useful for investigations. Drop in a bot token from malware and see threat actor comms directly from a clean web interface. Demo video attached. Let me know your thoughts!