Pillar
Endpoint security is the agent on the laptop or the server, and the story vendors tell about that agent seeing everything. It does not. The useful question is what you can still see when the process, the identity, and the cloud account disagree.
Correlate more than the endpoint
Open the listAsk the host, not only the console
Open the listKeep the laptop a company laptop
Open the listQuestions about Endpoint Security
Because the products teams are sold as endpoint security now sell themselves as XDR. The job we judge is correlation past the endpoint: identity, mail, cloud, the ticket. A high-scoring EDR that cannot leave the host will read as incomplete on that list.
CrowdStrike Falcon, Microsoft Defender XDR, LimaCharlie, Velociraptor, Fleet, and OpenEDR. Commercial platforms on one side, inspectable telemetry and response on the other. We care whether you can export the signal and whether the correlation is yours.
EDR is the agent and the host timeline. XDR is the claim that the same console will join that timeline to identity and cloud. We keep one list and say so in the job line, instead of pretending they are two finished categories.
No. If the product cannot give you a timeline you can query, it is not a list we will spend a page on.