<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Daniel Visovsky</title>
    <description>The latest articles on DEV Community by Daniel Visovsky (@danielvisovsky).</description>
    <link>https://dev.to/danielvisovsky</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3860925%2Fc4e5bd95-951e-4de6-bf69-4047e2e86971.png</url>
      <title>DEV Community: Daniel Visovsky</title>
      <link>https://dev.to/danielvisovsky</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/danielvisovsky"/>
    <language>en</language>
    <item>
      <title>What 14 EDR vendors won't tell you about source code, SBOMs, and update controls</title>
      <dc:creator>Daniel Visovsky</dc:creator>
      <pubDate>Sun, 17 May 2026 20:54:25 +0000</pubDate>
      <link>https://dev.to/danielvisovsky/what-14-edr-vendors-wont-tell-you-about-source-code-sboms-and-update-controls-4680</link>
      <guid>https://dev.to/danielvisovsky/what-14-edr-vendors-wont-tell-you-about-source-code-sboms-and-update-controls-4680</guid>
      <description>&lt;p&gt;Ever asked your EDR vendor for an SBOM or source code access? A recent study did it for 14 of them.&lt;/p&gt;

&lt;p&gt;Most security teams evaluate EDR-EPP based on detection rates and remediation features. But what about transparency? What data actually leaves your network? Can you review the code? Do you control updates?&lt;/p&gt;

&lt;p&gt;AV-Comparatives (commissioned by the Austrian Economic Chambers) looked at 14 leading cybersecurity vendors - including CrowdStrike, Microsoft, SentinelOne, Trellix, Kaspersky, Cisco, and others - on criteria that rarely make it into product brochures:&lt;/p&gt;

&lt;p&gt;Ability to review source code&lt;br&gt;
SBOM (Software Bill of Materials) availability&lt;br&gt;
Telemetry control and opt-out options&lt;br&gt;
Staged update rollouts&lt;br&gt;
On-prem reputation services&lt;br&gt;
Data residency and legal compliance&lt;br&gt;
The results are uneven. Only 3 vendors allow enterprise customers to review source code. Only a handful provide SBOMs. Just 8 out of 14 offer staged updates - which matters a lot after the CrowdStrike incident.&lt;/p&gt;

&lt;p&gt;The full report (including a breakdown by vendor) is available through AV-Comparatives. Link in the first comment if anyone wants to dig through the methodology.&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
