EDR Telemetry
Also called endpoint detection and response logs, endpoint telemetry, EDR process tree, security agent logs.
- PLATFORM
- Cross-platform
- CATEGORY
- Network and Remote Activity
- INDEX
- 33 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
Security-agent telemetry recording process execution with command lines and hashes, file operations, and outbound network connections — the richest endpoint record available, retained on the vendor's terms.
Where it lives
Vendor cloud console and its export interfaces; a local agent cache exists on the endpoint but is generally not the authoritative record
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of edr telemetry” is neither.
What it records
An endpoint agent reports events to a vendor platform: process creation with parent, command line and file hash; file creation, modification and deletion; registry changes; outbound network connections with destination and port; and device events including removable media. The console presents a normalised view assembled from that telemetry. What is retained, at what fidelity, and for how long is set by the product tier and the customer's contract rather than by anything in the operating system.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- Process execution with the full command line and a file hash, which resolves both the execution question and the identification question in one record
- Process ancestry, showing what launched what — the difference between a user action and a scripted or remote one
- Outbound connections with destination and port, which is the destination information endpoint artifacts do not supply
- File and removable-media operations correlated with the process that performed them
- Coverage across a fleet, so the same question can be asked of every endpoint rather than one imaged laptop
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Anything about periods or machines the agent did not cover. Agents are deployed unevenly, endpoints go offline, and exclusions are configured — coverage has to be established before an absence means anything
- That the console view is the evidence. What a console displays is a normalised, vendor-interpreted rendering; a defensible production requires the underlying telemetry export, and the difference is a standard cross-examination line
- That retained data reaches the period at issue. Retention is contractual and frequently short at the hot tier, and telemetry is often aggregated or sampled away as it ages
- Intent, or the content of what moved. A network connection and a byte count are not the material transferred
- That the account named performed the act. The same account-is-not-a-person limit applies to telemetry as to any log
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing agent coverage gaps — offline periods, unmanaged devices, exclusions — that make the dataset partial
- Demanding the raw telemetry export behind a console screenshot and showing the normalised view lost or transformed fields
- Attacking retention: the period that matters was purged before preservation, so what was produced is a fragment
- Questioning vendor-side interpretation, since the classification and enrichment logic is proprietary and not available for examination
What survives, and for how long
Retention is a commercial term rather than a technical one, and the hot searchable window at many tiers is short. Preservation means telling the vendor and the customer to hold and export before the window closes, because nothing on the endpoint reproduces it afterwards.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Is EDR telemetry good evidence in litigation?
It is the richest endpoint record available — process execution with command lines and hashes, file operations, and outbound network connections with destinations — and it is governed by a retention term rather than by the operating system. That combination makes it decisive when preserved in time and unavailable when not. The single most important step is a preservation demand to the vendor and customer before the window closes.
Why is a screenshot of an EDR console not enough?
Because the console displays a normalised, vendor-interpreted rendering of the underlying telemetry rather than the telemetry itself. Fields are transformed, enriched and sometimes summarised. A defensible production is an export of the underlying records with the query that produced them, and an opinion resting only on console screenshots invites a direct challenge to its foundation.
What does an absence of EDR alerts prove?
Very little on its own. Agents are deployed unevenly, endpoints spend time offline, exclusions are configured for performance and compatibility, and the product is tuned for detecting attacks rather than recording ordinary insider activity. Establishing coverage — which machines, over which periods, with which exclusions — has to come before any inference is drawn from silence.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Process Creation Events (4688)
A Security log record written each time a process starts, naming the account, the executable, the parent process and — if separately enabled — the full command line.
Microsoft Defender Logs
Antivirus detection and scan records that name file paths, detected tool families, process images, and changes to protection settings such as newly added scan exclusions.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
SRUM (System Resource Usage Monitor)
A Windows database attributing network bytes sent and received, and application foreground time, to individual programs and user accounts in hourly buckets.
Whether the edr telemetryevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.