Terminology Index

Glossary

64 terms starting with "E"

Open concept maps

Showing 1-32 of 64 terms

E
32

Endpoint Telemetry

The activity data collected from endpoints, process creation, file and registry changes, network connections, logons, that feeds detection and investigation. It is one of the richest and most important telemetry sources for defenders.

Endpoint telemetry, gathered by EDR, Sysmon, and OS logging, captures what actually happens on hosts: which processes ran, with what command lines and parents, what files and registry keys changed, and what connections were made. Because endpoints are where attacker code executes, this telemetry is essential for detection, hunting, and forensics, and ensuring it is collected with good coverage is a foundational logging decision.

Introduced in: Logging, Monitoring, and Telemetry

Examples

  • Recording process creation with full command lines via Sysmon or EDR.
  • Capturing file and registry changes on a host for investigation.
  • Using endpoint telemetry to reconstruct what an attacker did on a machine.

No related terms linked yet.