Skip to content

Added RCP Event Logging#134

Open
Sree-Nivetha wants to merge 1 commit intotsale:mainfrom
Sree-Nivetha:feat/add-rpc-telemetry-windows
Open

Added RCP Event Logging#134
Sree-Nivetha wants to merge 1 commit intotsale:mainfrom
Sree-Nivetha:feat/add-rpc-telemetry-windows

Conversation

@Sree-Nivetha
Copy link

EDR Telemetry Pull Request

Contribution Details

Adding telemetry field mapping for Process Creation events on Windows.

Telemetry Validation

The data provided directly relates to a security-relevant event (process creation) and details the execution context (command line, parent process, user). This meets the core telemetry definition.

Documentation or Evidence:

  • [x ] Official documentation (link: [https://docs.edr-vendor.com/telemetry/events/process_creation)
  • Screenshots attached
  • Sanitized logs provided
  • Private documentation (will share confidentially)

Type of Contribution

  • [x ] Adding telemetry information for an existing EDR product
  • Adding a new EDR product that meets eligibility criteria
  • Proposing new event categories/sub-categories
  • Documentation improvement
  • Tool enhancement

Validation Details

EDR Product Information

  • EDR Product Name: SentinelOne
  • EDR Version: Agent 22.3.5.1
  • Operating System(s) Tested: Windows 10 Pro (21H2)

Testing Methodology

Additional Notes

@tsale tsale added the backlog label Nov 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants