Kostas

@kostastsale.bsky.social

Running โžก http://defendpoint.ca | http://edr-telemetry.com | https://edr-comparison.com/ | http://detectionstream.com | ๐Ÿ‡ฌ๐Ÿ‡ท๐Ÿ‡จ๐Ÿ‡ฆ

๐Ÿ“ข๐Ÿ macOS is now part of the EDR Telemetry Project. After three months of focused work, weโ€™re excited to share a new framework and generator for endpoint visibility on macOS! Huge thank you to everyone who contributed and helped shape this release. Looking forward to what comes next.

macOS EDR Telemetry: A Structured Framework for Evaluating Endpoint Visibility.

EDR Telemetry Project - Exploring telemetry capabilities of EDR solutions

edr-telemetry.com

Itโ€™s been quiet on the EDR Telemetry side lately while working on something big! EDR telemetry's goal was always to set the standard for telemetry visibility, and this is what we're planning to do with tomorrow's release... Keep an eye out for tomorrow's announcement!

Bild

Phantom Stealer has been prominent across phishing campaigns over the past two weeks. Operationally interesting to me is that itโ€™s not just an infostealer. It also acts as an initial access broker, dropping GuLoader for follow-on activity, and Iโ€™ve seen it deploy crypto miners as well.

Bild

Clinejection PoC: researcher proved you can compromise a VS Code extension (700k+ weekly users) via prompt injection in GitHub issues. He was kind enough to install harmless software as a POC. Real attackers won't... Vendor ignored him for 47 days, fixed it in 30 min after he went public.

Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

### Description On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...

github.com

MDX content is awesome, I love it, and I use it whenever I can on my projects. But be careful cause if youโ€™re usingย next-mdx-remoteย (4.3.0โ€“5.x) to serverโ€‘side render untrusted MDX, youโ€™re potentially exposing yourself to RCE via CVEโ€‘2026โ€‘0969...

HCSEC-2026-01 - Arbitrary code execution in React server-side rendering of untrusted MDX content

Bulletin ID: HCSEC-2026-01 Affected Products / Versions: next-mdx-remote from 4.3.0 up to 5.0.0, fixed in 6.0.0. Publication Date: February 11, 2026 Summary The serialize function used to compileโ€ฆ

discuss.hashicorp.com

At EDR Telemetry project, we spend a lot of time measuring what EDRs can see. This article is about what they still cannot safely stop. From LOLBAS to vulnerable drivers to unauthorized RMMs, I walk through the real-world gaps we keep seeing in telemetry and why application control is...

Why Your EDR Needs a Partner: The Case for Application Control

How threat intelligence-aware application control fills the gaps that EDR leaves open

edr-telemetry.com

We have added a new analysis Skill thanks to @BlueTeamSteve! This skill can be used to quickly and accurately map the MITRE ATT&CK tactic and technique to threat behaviors and indicators you enter in the prompt, saving you a ton of time!

github.com

๐—˜๐——๐—ฅ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—ฃ๐—น๐—ฎ๐˜๐—ณ๐—ผ๐—ฟ๐—บ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ: ๐—ก๐—ฒ๐˜„ ๐—œ๐—ป๐˜๐—ฒ๐—ฟ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—˜๐˜…๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ, ๐— ๐—œ๐—ง๐—ฅ๐—˜ ๐—”๐—ง๐—ง&๐—–๐—ž ๐—œ๐—ป๐˜€๐—ถ๐—ด๐—ต๐˜๐˜€, ๐—ฎ๐—ป๐—ฑ ๐—ช๐—ฎ๐˜๐—ฐ๐—ต๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—˜๐——๐—ฅ We want to start by thanking everyone who supported us as early adopters.

EDR Comparison - Compare Endpoint Detection & Response Solutions

Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

edr-comparison.com

๐—๐˜‚๐˜€๐˜ ๐—น๐—ฎ๐˜‚๐—ป๐—ฐ๐—ต๐—ฒ๐—ฑ ๐—ฎ๐˜„๐—ฒ๐˜€๐—ผ๐—บ๐—ฒ-๐—ฑ๐—ณ๐—ถ๐—ฟ-๐˜€๐—ธ๐—ถ๐—น๐—น๐˜€ ๐˜„๐—ถ๐˜๐—ต @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and Iโ€™ve added a couple of timeline analysis skills to help you get started.

GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners.

A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills

github.com

Weโ€™ve just added ๐—–-๐—ฃ๐—ฟ๐—ผ๐˜ EDR to the EDR Telemetry Project and it sets a new bar for Linux telemetry! C-Prot is currently #1 in the Linux EDR table, with exceptional depth and quality of raw telemetry. What really stands out is the level of transparency: we got direct access to a production...

Add C-Prot telemetry coverage to Linux EDR telemetry matrix by tsale ยท Pull Request #151 ยท tsale/EDR-Telemetry

EDR Telemetry Pull Request Contribution Details Adding comprehensive Linux telemetry support for C-Prot EDR, including detailed event mappings, field explanations, and validation artifacts. This co...

github.com

Iโ€™ve moved all of my blog posts from Medium to a new blog section on my personal website. If youโ€™re looking for a good read, Iโ€™d recommend my Cobalt Strike write-ups (Part 1 & Part 2) from 2021โ€“2022. kostas.page/blog/cobalt-...

Cobalt Strike, a Defender's Guide - Part 2

The second part of the Cobalt Strike defender's guide, focusing on network traffic analysis and practical detection methods to identify Cobalt Strike beacons in your environment.

kostas.page

Many large companies are using AI and forcing their employees to use their AI models. They do this to train their AI models, getting them ready to replace many low-level analyst positions. If you are a security analyst in one of these big organizations, you need to have plan Bโ€ฆ.

๐Ÿ“ข ๐—œโ€™๐—บ ๐—ฎ๐—ป๐—ป๐—ผ๐˜‚๐—ป๐—ฐ๐—ถ๐—ป๐—ด ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—›๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ๐—Ÿ๐—ฎ๐—ฏ๐˜€, ๐—น๐—ฎ๐˜‚๐—ป๐—ฐ๐—ต๐—ถ๐—ป๐—ด ๐—ป๐—ฒ๐˜…๐˜ ๐˜†๐—ฒ๐—ฎ๐—ฟ! After building threat hunting teams for large MSSPs, creating DFIR Labs for TheDFIRReport, and sharing years of free threat hunting material, I want to bring everything together into one platform. Something closer to how investigations...

ThreatHunting Labs | Real Intrusion Training

Hands-on threat hunting labs built from real intrusions, not simulations. Join the waitlist for early access.

threathuntinglabs.com

๐—œ๐—ป๐˜๐—ฟ๐—ผ๐—ฑ๐˜‚๐—ฐ๐—ถ๐—ป๐—ด: ๐—ง๐—ฟ๐—ฎ๐—ป๐˜€๐—ฝ๐—ฎ๐—ฟ๐—ฒ๐—ป๐—ฐ๐˜† ๐—œ๐—ป๐—ฑ๐—ถ๐—ฐ๐—ฎ๐˜๐—ผ๐—ฟ๐˜€ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—˜๐——๐—ฅ-๐—ง๐—ฒ๐—น๐—ฒ๐—บ๐—ฒ๐˜๐—ฟ๐˜† ๐—ฃ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜! Transparency has always been central to the EDR Telemetry Project. Evaluations may involve different levels of access, and making that visible adds helpful context for readers.

Behind the Curtain: How the EDR Telemetry Project Approaches Vendor Relations, Evaluations, and Transparency

Introducing transparency indicators and explaining how we validate telemetry while staying independent.

edr-telemetry.com

โŠ•Weโ€™ve added ๐—–๐—ถ๐˜€๐—ฐ๐—ผ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—˜๐—ป๐—ฑ๐—ฝ๐—ผ๐—ถ๐—ป๐˜ to the EDR-Comparison.com platform!! Cisco shows strength in prevention, indicator alerting, and response automation, with solid investigation visuals and well-documented APIs that integrate easily into broader security stacks. Itโ€™s a platform that leans more...

Bild

As we are are approaching our goal, starting January, weโ€™re updating the pricing for the ๐—˜๐——๐—ฅ ๐—™๐—ฒ๐—ฎ๐˜๐˜‚๐—ฟ๐—ฒ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ. The platform has grown far beyond the initial dataset, and the new pricing reflects the depth of work going into the next phase of the project. ๐—ช๐—ต๐—ฎ๐˜โ€™๐˜€ ๐—ฐ๐—ผ๐—บ๐—ถ๐—ป๐—ด ๐—ป๐—ฒ๐˜…๐˜:

EDR Comparison - Compare Endpoint Detection & Response Solutions

Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

edr-comparison.com

Iโ€™ve been getting a lot of questions lately about the difference between the ๐—˜๐——๐—ฅ ๐—ง๐—ฒ๐—น๐—ฒ๐—บ๐—ฒ๐˜๐—ฟ๐˜† ๐—ฃ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜ and the ๐—˜๐——๐—ฅ ๐—–๐—ผ๐—บ๐—ฝ๐—ฎ๐—ฟ๐—ถ๐˜€๐—ผ๐—ป ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ. Theyโ€™re related, but they solve completely different problems. Telemetry ๐—ถ๐˜€ ๐—ผ๐—ป๐—ฒ ๐—ฝ๐—ถ๐—ฒ๐—ฐ๐—ฒ ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ ๐—ฝ๐˜‚๐˜‡๐˜‡๐—น๐—ฒ. The comparison service ๐—น๐—ผ๐—ผ๐—ธ๐˜€ ๐—ฎ๐˜ ๐˜๐—ต๐—ฒ ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐˜€๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป.

EDR Comparison - Compare Endpoint Detection & Response Solutions

Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.

edr-comparison.com

Heads-up on CVE-2025-55182: a CVSS 10.0 pre-auth RCE affecting React Server Components 19.x. Can be triggered through malicious HTTP payloads, so there will be chaos when a POC comes out. On that note...there are many fake POCs circulating. Be careful what you run. A POC is not available yet.

Bild

๐Ÿšจ๐—•๐—ถ๐—ด ๐—ฑ๐—ฎ๐˜† ๐—ณ๐—ผ๐—ฟ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐—ฆ๐˜๐—ฟ๐—ฒ๐—ฎ๐—บ. ๐—ข๐—ป๐—ฒ ๐—ผ๐—ณ ๐—ผ๐˜‚๐—ฟ ๐—น๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜€๐˜ ๐—ฟ๐—ฒ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ๐˜€ ๐˜†๐—ฒ๐˜. The platform now supports official pySigma validation fully in-browser, compiled to WebAssembly. Same validation as sigma-cli. Thanks to @sifex from detection.studio for the inspiration behind the implementation. Hereโ€™s what we added:๐Ÿ‘‡

Bild

If youโ€™re trying to use Wazuh for threat hunting or incident response, stop wasting your time. Wazuh is fine for compliance and system visibility, but thatโ€™s where it ends.

๐—ฅ๐—ผ๐—ฎ๐—ฑ๐—บ๐—ฎ๐—ฝ ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ: the first milestone is done. The Interactive Comparison Interface now has its core engine in place. Good progress for week one, and more updates are coming along with more EDR vendors!

I'm reviving Teletracker. Missed working on it and it deserved a second life. I'm rt is way more useful for investigations. Drop in a bot token from malware and see threat actor comms directly from a clean web interface. Demo video attached. Let me know your thoughts!