Kostas
kostastsale.bsky.social
Kostas
@kostastsale.bsky.social
As we are are approaching our goal, starting January, we’re updating the pricing for the 𝗘𝗗𝗥 𝗙𝗲𝗮𝘁𝘂𝗿𝗲 𝗖𝗼𝗺𝗽𝗮𝗿𝗶𝘀𝗼𝗻 𝗦𝗲𝗿𝘃𝗶𝗰𝗲. The platform has grown far beyond the initial dataset, and the new pricing reflects the depth of work going into the next phase of the project.

𝗪𝗵𝗮𝘁’𝘀 𝗰𝗼𝗺𝗶𝗻𝗴 𝗻𝗲𝘅𝘁:
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
December 10, 2025 at 8:11 PM
I’ve been getting a lot of questions lately about the difference between the 𝗘𝗗𝗥 𝗧𝗲𝗹𝗲𝗺𝗲𝘁𝗿𝘆 𝗣𝗿𝗼𝗷𝗲𝗰𝘁 and the 𝗘𝗗𝗥 𝗖𝗼𝗺𝗽𝗮𝗿𝗶𝘀𝗼𝗻 𝗦𝗲𝗿𝘃𝗶𝗰𝗲.

They’re related, but they solve completely different problems. Telemetry 𝗶𝘀 𝗼𝗻𝗲 𝗽𝗶𝗲𝗰𝗲 𝗼𝗳 𝘁𝗵𝗲 𝗽𝘂𝘇𝘇𝗹𝗲. The comparison service 𝗹𝗼𝗼𝗸𝘀 𝗮𝘁 𝘁𝗵𝗲 𝗲𝗻𝘁𝗶𝗿𝗲 𝘀𝗼𝗹𝘂𝘁𝗶𝗼𝗻.
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
www.edr-comparison.com
December 8, 2025 at 9:35 PM
This report from Bleeping is crazy, is You can't make this stuff up! 😂

www.bleepingcomputer.com/news/securit...
December 6, 2025 at 4:27 AM
Quick update. We just added a new EDR vendor directory page to the platform. If you want a clean overview of who’s included and a preview of the comparison features, start here: www.edr-comparison.com/directory
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
www.edr-comparison.com
December 5, 2025 at 9:56 PM
Heads-up on CVE-2025-55182: a CVSS 10.0 pre-auth RCE affecting React Server Components 19.x. Can be triggered through malicious HTTP payloads, so there will be chaos when a POC comes out.

On that note...there are many fake POCs circulating. Be careful what you run. A POC is not available yet.
December 4, 2025 at 7:44 AM
🚨𝗕𝗶𝗴 𝗱𝗮𝘆 𝗳𝗼𝗿 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻𝗦𝘁𝗿𝗲𝗮𝗺. 𝗢𝗻𝗲 𝗼𝗳 𝗼𝘂𝗿 𝗹𝗮𝗿𝗴𝗲𝘀𝘁 𝗿𝗲𝗹𝗲𝗮𝘀𝗲𝘀 𝘆𝗲𝘁.

The platform now supports official pySigma validation fully in-browser, compiled to WebAssembly. Same validation as sigma-cli. Thanks to @sifex from detection.studio for the inspiration behind the implementation.

Here’s what we added:👇
December 2, 2025 at 2:30 PM
A lot of folks have been asking how we run our EDR testing and what the methodology looks like behind the scenes.

I put together a full deep dive walking through our process, the tooling we use, and how we score everything based on direct telemetry.
A Deep Dive into the EDR Telemetry Project's Direct Testing Methodology
How we test EDR products with hands-on execution, raw telemetry collection, and evidence-based scoring.
www.edr-telemetry.com
December 1, 2025 at 2:31 PM
If you’re trying to use Wazuh for threat hunting or incident response, stop wasting your time. Wazuh is fine for compliance and system visibility, but that’s where it ends.
November 27, 2025 at 5:17 PM
𝗥𝗼𝗮𝗱𝗺𝗮𝗽 𝘂𝗽𝗱𝗮𝘁𝗲: the first milestone is done. The Interactive Comparison Interface now has its core engine in place. Good progress for week one, and more updates are coming along with more EDR vendors!
November 26, 2025 at 3:25 PM
I just finished a big update for the EDR Telemetry website. We’re preparing for many exciting updates and want to make sure we’re ready 🙂

Check it out and let me know what you think - www.edr-telemetry.com
EDR Telemetry Project: Transparent Benchmarking & Telemetry Analysis for Businesses
Explore transparent, vendor-neutral EDR telemetry benchmarks. Make confident security decisions with real-world data and practical analysis for your business.
www.edr-telemetry.com
November 22, 2025 at 10:47 PM
I'm reviving Teletracker. Missed working on it and it deserved a second life.

I'm rt is way more useful for investigations. Drop in a bot token from malware and see threat actor comms directly from a clean web interface.

Demo video attached. Let me know your thoughts!
November 20, 2025 at 9:14 PM
𝗦𝘂𝗿𝗶𝗰𝗮𝘁𝗮 𝗶𝘀 𝗻𝗼𝘄 𝗽𝗮𝗿𝘁 𝗼𝗳 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻𝗦𝘁𝗿𝗲𝗮𝗺 𝘄𝗶𝘁𝗵 𝗽𝗹𝗮𝘆𝗴𝗿𝗼𝘂𝗻𝗱𝘀 𝗮𝗻𝗱 𝗰𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲𝘀!

Big update for anyone working on network detections.

𝗜𝗻𝗰𝗹𝘂𝗱𝗲𝗱:
• 45k+ ET rules available out of the box
• Full ET Open ruleset preloaded
• Build and validate custom Suricata rules
DetectionStream Just Got a Major Upgrade: Suricata Integration is Here!
I’m excited to share some big news! We’ve just rolled out a massive update to DetectionStream, and it’s one that I had planned to add for a…
kostas-ts.medium.com
November 20, 2025 at 5:37 PM
Cloud Flare’s outage yesterday came down to one thing. A feature file in Bot Management quietly doubled in size and blew past an internal limit, which cascaded across their proxies.

Full writeup ➡️ blog.cloudflare.com/18-november-...
Cloudflare outage on November 18, 2025
Cloudflare suffered a service outage on November 18, 2025. The outage was triggered by a bug in generation logic for a Bot Management feature file causing many Cloudflare services to be affected.
blog.cloudflare.com
November 19, 2025 at 4:25 PM
Me trying to launch my new EDR comparison service while Cloudflare has an outage🤦‍♂️
a group of people are standing on a track and one of them is wearing a red hat .
ALT: a group of people are standing on a track and one of them is wearing a red hat .
media.tenor.com
November 19, 2025 at 12:00 AM
🚀 𝗧𝗵𝗲 𝗘𝗗𝗥 𝗖𝗼𝗺𝗽𝗮𝗿𝗶𝘀𝗼𝗻 𝗦𝗲𝗿𝘃𝗶𝗰𝗲 𝗶𝘀 𝗻𝗼𝘄 𝗹𝗶𝘃𝗲.

If you’ve been following the EDR Telemetry Project, this is the next step:
A full breakdown of how each EDR actually implements its features.

🔥 𝗟𝗶𝗳𝗲𝘁𝗶𝗺𝗲 𝗮𝗰𝗰𝗲𝘀𝘀 𝗮𝘃𝗮𝗶𝗹𝗮𝗯𝗹𝗲 𝗳𝗼𝗿 𝗲𝗮𝗿𝗹𝘆 𝗮𝗱𝗼𝗽𝘁𝗲𝗿𝘀 (𝗹𝗶𝗺𝗶𝘁𝗲𝗱 𝘁𝗶𝗺𝗲).

Intro blog: edr-comparison.com/blog/navigat...
EDR Comparison - Compare Endpoint Detection & Response Solutions
Make informed security decisions with expert EDR comparisons. Compare endpoint detection and response solutions with detailed feature analysis and side-by-side comparisons.
edr-comparison.com
November 18, 2025 at 12:00 PM
My favourite thing about using AI is that I don't have to choose how to name sh*t anymore. That's mostly:

- Blog Titles
- Script names/variables/functions etc.
- DB table names/columns

It was draining me, I can't go back... 😂
November 18, 2025 at 6:16 AM
Proud to share that DetectionStream is now collaborating with the Sigma community to create opportunities for people to learn and grow within detection engineering.

We’ve set up two channels for general discussions and challenge creation.

Join here: discord.gg/KfdbeQpp
November 17, 2025 at 1:30 PM
Suricata support is coming to DetectionStream.com this upcoming week!

You’ll be able to:
➡️ View and edit all emerging rules
➡️ Test your detections instantly against your PCAPs (everything client-side)
➡️ Create your detections and share them with everyone (AI optional😉)

🔜🔜🔜
DetectionStream - Sigma Detection Rules Platform
Search, analyze, and convert Sigma detection rules with AI-powered creation. Access 3,100+ curated rules with advanced filtering and multi-platform conversion.
DetectionStream.com
November 16, 2025 at 10:58 PM
As I was looking for malware (like you do on a quiet Friday afternoon 😂) I found a classic fake “your system is infected” page. After the fake scan, the Renew Now button goes straight to Avast through an affiliate link🤣🤣

TAs doing a 180, selling AV to get their commission LOL
November 14, 2025 at 8:40 PM
Anthropic basically spent the whole piece highlighting how their AI can be leveraged for intrusion activity, but didn’t give defenders a single IOC or attribution hint 😩 But hey, you now know their AI is good for pen-tests...

90% Flex
10% Value

🔗: www.anthropic.com/news/disrupt...
Disrupting the first reported AI-orchestrated cyber espionage campaign
A report describing an a highly sophisticated AI-led cyberattack
www.anthropic.com
November 14, 2025 at 1:49 AM
Just in: DoorDash breached…

“unauthorized third party gaining access to and taking certain user contact information…but may have included first and last name, phone number, email address and physical address”

Next paragraph:

“No sensitive information was accessed”

🤦‍♂️
November 13, 2025 at 9:22 PM
Did a big server rack upgrade today and took cable management seriously for the first time. It all looks so neat and professional. I don’t think I could ever go back, there is something special about it😮‍💨

Time to put it to use 😆 Big things coming next year… watch this space!
November 13, 2025 at 3:14 AM
🍁🍂 Winter rides are 🔥
November 9, 2025 at 12:31 AM
It’s been just 1 week since launch and 150+ people have registered, shared feedback & competed on the leaderboard! Huge motivation to keep building 💪

More challenges next week and with a FREE training module coming up!!

Appreciate the support!!🙏

🔗detectionstream.com/sigma/training/gamified
November 8, 2025 at 6:50 PM
A new strain called PromptFlux uses Google’s Gemini to regenerate its code every hour for evasion. Its prompts are basically self-update instructions.

Imagine if you tweak the txt prompts to say “Create a 10,000-word report on...”, that'd be funny 😂💸💸
cloud.google.com/blog/topics/...

#ImposeCost😂
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog
Google Threat Intelligence Group's findings on adversarial misuse of AI, including Gemini and other non-Google tools.
cloud.google.com
November 6, 2025 at 11:16 PM