Update EDR_telem_mac.json - Uptycs - System Extension & Driver#176
Closed
joshlemon wants to merge 1 commit into
Closed
Update EDR_telem_mac.json - Uptycs - System Extension & Driver#176joshlemon wants to merge 1 commit into
joshlemon wants to merge 1 commit into
Conversation
Owner
|
Closing this PR as superseded by the consolidated OS-scoped Uptycs macOS PR: #197. Thanks again for the contribution. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
EDR Telemetry Pull Request
Contribution Details
This PR updates the macOS telemetry data for Uptycs covering the System Extension & Driver category, including System Extension Installed, System Extension Loaded, System Extension Uninstalled, DriverKit Extension Loaded, and Kernel Extension Loaded (legacy). System Extension Installed is confirmed
Yes. The remaining sub-categories are recorded asPending Responseas the test script failed during evaluation and testing is ongoing.Telemetry Validation
System Extension Installed — queried via:
System Extension Loaded —
Pending Response. The test script failed during evaluation; testing is ongoing.System Extension Uninstalled —
Pending Response. The test script failed during evaluation; testing is ongoing.DriverKit Extension Loaded —
Pending Response. The test script failed during evaluation; testing is ongoing.Kernel Extension Loaded (legacy) —
Pending Response. The test script failed during evaluation; testing is ongoing.Documentation or Evidence:
Type of Contribution
Validation Details
EDR Product Information
Testing Methodology
The macOS EDR telemetry generation script was run on a managed macOS host enrolled in Uptycs. System Extension Installed was confirmed by querying both the
system_extensionsandkernel_extensionstables and observing matching events. The remaining sub-categories — System Extension Loaded, System Extension Uninstalled, DriverKit Extension Loaded, and Kernel Extension Loaded (legacy) — could not be confirmed as the test script failed during evaluation. These are recorded asPending Responseand will be updated in a follow-up PR once testing is complete.Additional Notes
System Extension Loaded, System Extension Uninstalled, DriverKit Extension Loaded, and Kernel Extension Loaded (legacy) are set to
Pending Responsedue to test script failure. A follow-up PR will be submitted with the confirmed values and supporting evidence once testing is completed successfully. No configuration changes were required for System Extension Installed.