C-Prot Windows telemetry updates#196
Conversation
|
@husnuoner thank you for the C-Prot EDR telemetry contributions. For future submissions, please group related telemetry updates into a single pull request per operating system rather than opening one pull request per individual category or row. For example:
This makes review, validation, and merging much easier for the project. I’ve consolidated the current submissions into OS-scoped PRs here: Thanks again for contributing. |
|
@husnuoner - Can you please provide some information regarding the following?
|
|
@tsale thank you for the feedback. In addition to the telemetry logs, USB mount and unmount events are also captured under Peripheral Activity in our HIDS module. This provides detailed visibility into USB device connection and disconnection events at the endpoint level. CSC screenshot – showing the Peripheral Activity view with USB mount/unmount events These should confirm that USB mount/unmount activity is covered by both telemetry and HIDS, supporting a "Yes" rather than "Partially" designation.
csc_telemetry_peripheral-activity-log_2026-06-15T12-02Z_2026-06-16T12-02Z.json.gz |

EDR Telemetry Pull Request
Contribution Details
Consolidates the C-Prot Windows telemetry updates that were originally submitted as separate PRs for individual subcategories:
Changed file:
EDR_telem_windows.jsonTelemetry Validation
Documentation or Evidence:
This PR preserves the submitted C-Prot Windows changes as a single OS-scoped review unit. Evidence details remain as provided by the contributor in the original PRs and should be reviewed before publication/merge.
Type of Contribution
Validation Details
EDR Product Information
Testing Methodology
Not specified in the original PRs. This consolidation was validated mechanically by:
EDR_telem_windows.jsonas syntactically valid JSONAdditional Notes
This PR is intended to replace the individual C-Prot Windows PRs listed above so the project can review multiple same-OS telemetry changes in one pull request.