C-Prot macOS telemetry updates#195
Conversation
|
@husnuoner thank you for the C-Prot EDR telemetry contributions. For future submissions, please group related telemetry updates into a single pull request per operating system rather than opening one pull request per individual category or row. For example:
This makes review, validation, and merging much easier for the project. I’ve consolidated the current submissions into OS-scoped PRs here: Thanks again for contributing. |
Keep Raw Device Access accepted based on direct raw device access evidence, but leave Process Access and Process Injection Or Tampering as No because the submitted evidence is detection/prevention-oriented rather than direct telemetry.
|
Thanks for the evidence @husnuoner. Everything looks good except
|
EDR Telemetry Pull Request
Contribution Details
Consolidates the C-Prot macOS telemetry updates that were originally submitted as separate PRs for individual subcategories:
Changed file:
EDR_telem_macOS.jsonTelemetry Validation
Documentation or Evidence:
This PR preserves the submitted C-Prot macOS changes as a single OS-scoped review unit. Evidence details remain as provided by the contributor in the original PRs and should be reviewed before publication/merge.
Type of Contribution
Validation Details
EDR Product Information
Testing Methodology
Not specified in the original PRs. This consolidation was validated mechanically by:
EDR_telem_macOS.jsonas syntactically valid JSONAdditional Notes
This PR is intended to replace the individual C-Prot macOS PRs listed above so the project can review multiple same-OS telemetry changes in one pull request.