Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
Prevention stops what it recognises. Detection and response records what got through so a person can find it and act — and without that person, the EDR console is the most expensive dashboard nobody opens.
Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention only. The EDR is Plan 2, and that is in E5. Check the SKU before assuming you own detection.
Already decided — before the detection-rate chart
Still yours to weigh
An agent on every laptop, desktop, server and (usually) phone that does two jobs. The first is prevention: block known malware, exploit techniques and ransomware behaviour before they run — the antivirus lineage, now machine-learning and behaviour-based. The second is detection and response: record process, file, network and identity events continuously, raise what looks wrong, and give a person the tools to investigate and act — isolate the machine, kill the process, roll files back, hunt across the estate.
The first job runs itself. The second does not — it produces alerts, and alerts need someone with time and skill to read them. That is why every vendor on this page also sells people: a managed detection and response service that runs the console for you (its own guide is here). Whether you need the second job, and who will do it, decides this purchase more than any detection-rate chart.
The honest cut
EDR without someone to triage it is shelfware with a licence fee. If nobody on your side will open the console daily, buy the managed tier or stay with prevention — and say so in the evaluation, because the vendor’s demo will not.
Often confused withManaged Detection & Response — a tool, versus someone to run it →·UEM & MDM — configuring and proving the fleet, not fighting what's on it →·Vulnerability Management — what could be attacked, versus what is being attacked →·Cyber Recovery — where ransomware prevention meets ransomware recovery →
Three letters that every vendor sells as tiers. They are not better-worse; they are narrower-wider. Each one widens the scope of what is recorded — and each widening costs more and needs more people to read what it records.
EPP — Endpoint Protection Platform
Prevention at the endpoint: block known malware, exploit techniques and ransomware behaviour before they run. The console is for policy and reporting; it runs itself. Every vendor's entry tier. Broad enough for many estates under ~300 seats that accept nothing is hunting.
EDR — Endpoint Detection & Response
Continuous recording of process, file, network and identity events on the endpoint, alerts on what looks wrong, and a console to investigate, isolate, kill, hunt — and at some vendors roll files back. It produces work for a person every day. Not 'better EPP'; a different job that assumes EPP missed something.
XDR — Extended Detection & Response
EDR's recording joined with email, identity, cloud and network signals so one incident is one story. Wider scope again — more to see, more to staff, and worth it only when those other sources exist and someone correlates them. Platform vendors sell it as the reason to buy everything from them.
Seven variables decide this purchase — the instrument tests the ones documentation can verify; the rest are prose because the honest answer depends on your team.
Prevention depth vs detection-and-response depth
Which job you are buying — the entry tier blocks, the higher tier records and lets a person respond. Every vendor sells both; the price gap is the second job.
Who operates it
The honest cut. An EDR with no one to triage it is shelfware — so the chip asks whether the vendor sells the people too, and whether that managed tier is priced for you or enterprise-gated.
Agent coexistence
What is already on the machine: UEM, RMM, backup, an old AV. One real-time engine per machine; Windows steps Defender aside automatically; two third-party engines do not coexist.
Rollback and remediation
Four mechanisms and one absence — protected-copy restore, agent-level rollback, containment, restore-from-backup, or isolate-and-kill only. Know which you bought before the first incident.
Managed option availability
Whether the vendor's own 24/7 service exists for this SKU, what it covers, and what it costs — the MDR guide takes it from here.
Platform bundling vs best-of-breed
One suite (Microsoft, Sophos, Trend, Kaspersky, Bitdefender, ESET) or the best agent most consoles integrate (CrowdStrike, SentinelOne) — and the UEM / RMM / backup vendors selling security inside their console. Convenience versus depth; the card's limitation tells you the price.
India data residency
Documented for SentinelOne and Sophos (Mumbai), Seqrite, Acronis, Scalefusion; announced for CrowdStrike; unknown for most. The instrument never eliminates on 'unknown' — it flags and you ask in writing.
Choose the constraints that are true for you. Products that fail one fade in place with the reason written on them; products we cannot verify for your case are marked and stay in. Every chip is reversible; nothing leaves the page.
Hosting
Prevention or response
Commercial shape
Platforms
Ransomware recovery
Who runs it
Fleet size
India data residency, platform bundling and agent coexistence remove nothing as chips — their reasoning is in the notes below and in the four-letters section. Prevention vs EDR is the one cut every vendor's price list makes.

per device / year — Falcon Go (prevention) · Pro; the reference cloud-native agent
Teams that want CrowdStrike's prevention agent today and a path to Insight EDR tomorrow without a second install.
The catch: Prevention only — no timeline, hunting or response until you add Insight; no file rollback; India in-country cloud is announced, not yet documented live.

per device / year (Falcon Enterprise bundle with Prevent); Falcon Complete MDR on quote
Security teams that will hunt — the reference EDR telemetry, forensic timeline and Real Time Response.
The catch: An EDR that needs operators: no automatic file rollback, Falcon Complete (managed) is enterprise-priced on quote, and the bundle is the cloud-only Falcon platform.

per endpoint / year reseller list (Core · Control · Complete); Vigilance MDR add-on; Mumbai region
Autonomous prevention-to-response on one agent with documented one-click rollback and an India data region.
The catch: No vendor-published list (street price varies widely), no on-prem console; mobile is a paid Singularity Mobile add-on.

per user / month standalone (P1 prevention / P2 EDR); $0 marginal when bundled
Microsoft 365 estates — the EPP/EDR you may already hold, with the tightest Intune and Entra integration there is.
The catch: E3 carries only P1 (no EDR); file rollback is OneDrive Files Restore, not the agent; Defender Experts (managed) needs E5 and a quote; the console assumes a Microsoft estate.

per user / year (reported ~$30–50); Sophos Central; Mumbai region
Prevention with CryptoGuard file rollback for teams that want Sophos MDR to be the default operating model later.
The catch: The Advanced SKU is prevention — detection and response is the separate 'with XDR' tier; no published list; CryptoGuard rollback needs ~3 GB free disk.

per user / year (reported ~$48); adds XDR data lake, cross-product detections; Mumbai region
Teams that want EDR/XDR on the Sophos agent with the MDR tier one step away.
The catch: Estimates only — no published list; XDR breadth across email / firewall / cloud is a Sophos-estate story; no on-prem console.

per device / year — Small Business · Business Security (EPP); Premium adds EDR
Price-sensitive mixed fleets wanting published per-device prevention with Ransomware Mitigation and an on-prem console option.
The catch: Prevention tier — EDR is the Premium SKU; first-year promotional pricing renews at standard rates (users report 2–3×); India cloud region not documented.

per device / year (Business Security Premium with EDR); XDR / Enterprise on quote
Bitdefender prevention plus a real EDR tier, with MDR available from the same vendor.
The catch: XDR and Enterprise are quote-only; the published Premium price is first-year promotional; India region not documented.

add-on to GravityZone — proactive hardening and attack-surface reduction per user behaviour
GravityZone estates that want the attack surface tailored per user before prevention ever has to fire.
The catch: An add-on, not standalone protection — it hardens, it does not detect or roll back; quote-only.
per device / year (5-device packs); endpoint + file-server protection
Lean teams wanting a light agent, published pricing, on-prem or cloud console and Ransomware Remediation.
The catch: Prevention only — no EDR (Elite), no mobile (Advanced+), no sandbox; ESET MDR is a separate quote.
per device / year; adds cloud sandbox, full-disk encryption, Mobile Threat Defense
ESET Entry plus sandboxing, encryption and phones in the same console.
The catch: Still prevention — EDR arrives only at Elite (quote, 25-device minimum); India cloud region not documented.
per device / year; adds Microsoft 365 / Google Workspace protection, mail server, vulnerability & patch
One ESET console for endpoint, mail and patching in a small estate.
The catch: Breadth without EDR — detection and response is the Elite tier; the M365 / Workspace protection is email filtering, not an EDR for mail.
per device / year, 25-device minimum; adds ESET Inspect (XDR) and MFA
ESET estates that outgrew prevention and want the XDR tier and ESET MDR on the same agent.
The catch: Quote-only with a 25-device minimum; ESET Inspect is an operator's console — budget the analyst or the MDR.
per endpoint / month — Essentials · Standard · Advanced; Apex One on-prem still sold
Estates that want Trend's endpoint sensor feeding Vision One XDR, with Service One MDR from the same vendor.
The catch: Advanced is the EDR-grade tier at ~6× Essentials; credit-based Vision One billing is hard to forecast; automatic file rollback is not documented.
Vision One credits, annual; correlates endpoint, email, network, cloud, identity
Trend estates correlating endpoint with email, network and cloud telemetry in one platform.
The catch: Needs Trend sensors to be worth it; credit consumption is opaque until you run it; no published list.

per 5 users / year (Foundations); Optimum / Expert and MXDR on quote; on-prem or cloud console
Estates wanting a full prevention-to-EDR ladder with the Remediation Engine rollback and an MXDR option on the same agent.
The catch: Procurement-sensitive in some sectors and countries (US ban; check your regulator); EDR Expert is enterprise-priced; India data region not documented.

per user / year, cloud console; Pro / Plus tiers add EDR Optimum-grade features
Small estates wanting Kaspersky prevention with phones included and nothing to host.
The catch: Prevention-first — full EDR is the Next line; cloud-only; the same procurement caveats as Kaspersky Next.

per endpoint / year, INR-native (EPS Core → Total); EDR / XDR on quote
India-regulated estates that need CERT-In-empanelled, INR-billed, on-prem endpoint protection with local support.
The catch: Prevention tier — EDR/XDR are separate SKUs; mobile is mSuite (separate console); ransomware recovery restores from its own backup rather than rolling back; scale above 2,000 claimed, not documented.

per endpoint / year, INR-native, India-hosted cloud console
The same Seqrite protection with nothing to host and data in India.
The catch: Cloud-only variant of a prevention tier; EDR/XDR are add-ons; scale above 2,000 endpoints not documented.

add-on per endpoint / year (≈ ₹350 over EPS Core reported); INR-native
Seqrite estates adding detection and response without leaving the India-hosted stack.
The catch: An add-on to EPS, not standalone; quote-only; depth of hunting and telemetry retention is not documented at the level CrowdStrike or SentinelOne publish.

per endpoint / year, INR-native; correlates Seqrite endpoint, network and cloud telemetry
India estates wanting XDR and MDR from one CERT-In-empanelled vendor.
The catch: XDR breadth is Seqrite-stack-first; quote-only; unverified above 2,000 endpoints.
per endpoint / month, modular and postpaid; OpenEDR free to 50 endpoints
Teams that want unknown files contained at the kernel before they run — a different bet from detect-then-respond.
The catch: Containment is the mechanism, not rollback — nothing to restore because nothing ran, and no file-restore if something is allowed; on-prem and India region not documented.
per endpoint / month module; runs beside Microsoft Defender (documented)
An EDR module that can sit on top of Defender AV or the Xcitium stack.
The catch: Module pricing adds up; unverified above 2,000 endpoints; India region not documented.
per endpoint / month module; network, cloud and endpoint telemetry
Xcitium estates widening the recording beyond the endpoint.
The catch: XDR depth is Xcitium-stack-first; scale and region unverified.
open-source EDR, free to 50 endpoints; paid platform beyond
Teams that want real EDR telemetry for nothing, and will run it themselves.
The catch: Windows-only, EDR-only (no prevention engine), nobody watches it but you — shelfware unless someone reads the console daily.

per user / year reported (Basic · Advanced · Complete); on-prem or Infinity cloud management
Check Point estates wanting prevention-first endpoint with anti-ransomware restore and Infinity-portal management.
The catch: No published list (reported ranges only); managed service is enterprise-gated; India data region not documented.

per user / month (Essentials); Advantage / Premier (XDR, hunting) on quote; private-cloud appliance option
Cisco-network estates wanting endpoint telemetry that joins Umbrella, Secure Firewall and Cisco XDR.
The catch: Only Essentials is published; the XDR and hunting tiers are quote-only; file rollback not documented; mobile not covered.

per user / year reported (Essentials · Advantage · Premier); correlates Cisco and third-party telemetry
Cisco estates correlating endpoint, network, email and identity in one console.
The catch: Needs sources to correlate — alone it is a console; quote-only; no rollback; cloud-only.

per endpoint / year reported; on-prem or cloud; FortiGuard MDR option
Fortinet Security Fabric estates wanting pre- and post-infection protection with an MDR option on the same agent.
The catch: No published list; automatic file rollback not documented; no mobile coverage; strongest inside a Fortinet stack.

per workload / month (Advanced with EDR, India reseller list); cloud or on-prem; Mumbai data centre
Estates that want backup and EDR in one agent — recovery is a restore, not a rollback.
The catch: Recovery means restoring from Acronis backup (strong, but not automatic rollback); EDR depth is below the pure-play leaders; per-workload pricing climbs with servers.

per user / month, modular (historically ~$7.50–10.50); managed SOC option
SMBs that want endpoint, email, cloud-app and posture in one modular agent with a managed option.
The catch: Linux agent is remote scan-only; no documented file rollback; public list withdrawn in 2026; unverified above 2,000 endpoints.

per year for 10 devices (first year; Premium $299.99); up to 20 devices
Very small businesses that want consumer-grade antivirus with a business licence and nothing to manage.
The catch: Licensed for up to 20 devices — not an enterprise product; no EDR, no Linux, no console for compliance evidence, no managed option.

per device / month; UEM-native endpoint security inside the Hexnode console
Hexnode UEM estates that want threat protection in the console they already run.
The catch: A young product from a UEM vendor — EDR depth, Linux coverage and rollback are not documented; no managed service; unverified at scale.

per device / month reported; UEM-native: web filtering, DLP, VPN/ZTNA, compliance
Scalefusion UEM estates adding web filtering, DLP and zero-trust access from the same India-hosted console.
The catch: Not an anti-malware engine — no detection and response, no rollback; a hardening and access layer beside your EPP, not instead of it.

per endpoint / month reported, on top of the NinjaOne RMM seat; resold Bitdefender or SentinelOne engine
NinjaOne RMM estates that want the EDR engine deployed and watched from the RMM console.
The catch: You buy the RMM first; the engine is Bitdefender or SentinelOne with their capabilities — rollback and managed options depend on which; NinjaOne regions are US/EU/CA/OC, no India.
On-prem management consoleRules out CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Trend Vision One XDR, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection Cloud, Cisco XDR, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — cloud-only console. That leaves Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite Endpoint Protection (on-prem), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR and Acronis Cyber Protect (EDR). It flags Xcitium ZeroDwell (containment) — On-prem option not documented either way, Xcitium EDR — On-prem option not documented either way and Xcitium XDR — On-prem option not documented either way — marked on the cards, not removed.
Full EDRRules out CrowdStrike Falcon Prevent (Go / Pro), Sophos Intercept X Advanced, Bitdefender GravityZone Business Security, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Norton Small Business and Hexnode XDR — a prevention-tier SKU; EDR is a higher tier or a separate product; Bitdefender GravityZone PHASR and Scalefusion Veltar — a hardening / access add-on, not detection and response. That leaves CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne).
Prevention only is enoughRules out CrowdStrike Falcon Insight XDR, Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR and Cisco XDR — an EDR / XDR SKU that needs operators and a prevention engine beside it; Bitdefender GravityZone PHASR and Scalefusion Veltar — an add-on that needs a protection engine beside it. That leaves CrowdStrike Falcon Prevent (Go / Pro), SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne).
Vendor-published list priceRules out SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone PHASR, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Check Point Harmony Endpoint, Cisco XDR, Fortinet FortiEDR, Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — quote-only (reported ranges at most). That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Cisco Secure Endpoint, Acronis Cyber Protect (EDR), Norton Small Business, Hexnode XDR and Scalefusion Veltar.
Linux servers with real-time protectionRules out Xcitium OpenEDR and Norton Small Business — no Linux coverage; Coro Endpoint & EDR — Linux agent is scan-only, no real-time protection. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Linux coverage not documented, Hexnode XDR — Linux coverage not documented and Scalefusion Veltar — Linux coverage not documented — marked on the cards, not removed.
Phones and tablets in the same consoleRules out Bitdefender GravityZone PHASR, ESET PROTECT Entry, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium OpenEDR, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR) and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — no mobile coverage in this SKU. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar. It flags CrowdStrike Falcon Prevent (Go / Pro) — Mobile is a paid add-on to the same console, CrowdStrike Falcon Insight XDR — Mobile is a paid add-on to the same console, SentinelOne Singularity Endpoint — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced with XDR — Mobile is a paid add-on to the same console, Bitdefender GravityZone Business Security — Mobile is a paid add-on to the same console, Bitdefender GravityZone EDR / XDR (Premium · Enterprise) — Mobile is a paid add-on to the same console, Trend Vision One Endpoint Security — Mobile is a paid add-on to the same console, Trend Vision One XDR — Mobile is a paid add-on to the same console and Check Point Harmony Endpoint — Mobile is a paid add-on to the same console — marked on the cards, not removed.
Automatic file rollbackRules out CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Cisco XDR, Coro Endpoint & EDR, Norton Small Business and Scalefusion Veltar — no documented automatic file rollback (response is isolate, kill, restore from your own backups). That leaves SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Rollback not documented either way, Trend Vision One Endpoint Security — Rollback not documented either way, Trend Vision One XDR — Rollback not documented either way, Seqrite Endpoint Protection (on-prem) — Restores from its own backup rather than automatic rollback, Seqrite Endpoint Protection Cloud — Restores from its own backup rather than automatic rollback, Seqrite EDR — Restores from its own backup rather than automatic rollback, Seqrite XDR (HawkkHunt) — Restores from its own backup rather than automatic rollback, Xcitium ZeroDwell (containment) — Prevents by containing unknown files before they run, Xcitium EDR — Prevents by containing unknown files before they run, Xcitium XDR — Prevents by containing unknown files before they run, Xcitium OpenEDR — Rollback not documented either way, Cisco Secure Endpoint — Rollback not documented either way, Fortinet FortiEDR — Rollback not documented either way, Acronis Cyber Protect (EDR) — Restores from its own backup rather than automatic rollback, Hexnode XDR — Rollback not documented either way and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — Rollback not documented either way — marked on the cards, not removed.
Nobody to triage alertsRules out Xcitium OpenEDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar — no managed detection service from the vendor. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags CrowdStrike Falcon Prevent (Go / Pro) — Managed tier is enterprise-gated (quote / E5), CrowdStrike Falcon Insight XDR — Managed tier is enterprise-gated (quote / E5), Microsoft Defender for Endpoint P1 / P2 — Managed tier is enterprise-gated (quote / E5), Check Point Harmony Endpoint — Managed tier is enterprise-gated (quote / E5), Cisco Secure Endpoint — Managed tier is enterprise-gated (quote / E5) and Cisco XDR — Managed tier is enterprise-gated (quote / E5) — marked on the cards, not removed.
Above 2,000 endpointsRules out Norton Small Business — licensed for up to 20 devices. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Seqrite Endpoint Protection (on-prem) — Unverified above 2,000 endpoints, Seqrite Endpoint Protection Cloud — Unverified above 2,000 endpoints, Seqrite EDR — Unverified above 2,000 endpoints, Seqrite XDR (HawkkHunt) — Unverified above 2,000 endpoints, Xcitium ZeroDwell (containment) — Unverified above 2,000 endpoints, Xcitium EDR — Unverified above 2,000 endpoints, Xcitium XDR — Unverified above 2,000 endpoints, Xcitium OpenEDR — Unverified above 2,000 endpoints, Coro Endpoint & EDR — Unverified above 2,000 endpoints, Hexnode XDR — Unverified above 2,000 endpoints and Scalefusion Veltar — Unverified above 2,000 endpoints — marked on the cards, not removed.
India data residencyDocumented: SentinelOne (Mumbai), Sophos Central (Mumbai), Seqrite (India data centres and on-prem), Acronis (Mumbai), Scalefusion Veltar (India-hosted). CrowdStrike announced an India in-country cloud in January 2026 — announced, not yet documented live. NinjaOne's regions are US / EU / CA / OC (no India). Not documented either way for the rest — so no chip, and nothing is ruled out on it. Ask for the region in writing.
Platform bundling vs best-of-breedNot a chip because it is a strategy, not a capability: Defender inside Microsoft 365, NinjaOne / Hexnode / Scalefusion beside a UEM or RMM, Acronis beside backup, Sophos / Trend / Kaspersky / Bitdefender / ESET as platform suites, CrowdStrike / SentinelOne as the best-of-breed agents most other consoles integrate. The instrument tells you what each SKU does; whether one console or two is the right trade is the operating-capacity question.
Agent coexistenceRules nothing out but decides the rollout: Windows drops Defender Antivirus to passive mode when another engine registers, so any EPP here coexists with Defender for Endpoint telemetry; Xcitium EDR documents running beside Defender; two third-party real-time engines do not coexist — and the RMM's or UEM's bundled security is the usual way a second one arrives.
Under 50 endpointsRules nothing out on published minimums — Xcitium OpenEDR is free to 50, ESET sells 5-device packs, Defender for Business is sized to 300 users, Bitdefender and CrowdStrike Falcon Go sell small packs, Norton covers up to 20. Which enterprise tiers are a poor fit at this size is delivery-team judgement: [TechBag to confirm].
Each shortlist states who will run it. If the answer is nobody, the shortlist changes — that is the point.
Why: Managed detection priced for mid-market, sold with the agent by the same vendor: Sophos leads with MDR as the default product, Bitdefender and ESET sell it on top of published tiers.
The trade-off: MDR scope is endpoint-first and the contract is what you are buying — read the scope on the Managed Detection & Response guide before the licence.
Why: Defender for Endpoint P2 is already paid for; a second EDR duplicates it. On E3 you hold only P1 — prevention — so the choice becomes E5 Security against a third-party EDR.
The trade-off: No file rollback in the agent, Defender Experts is a quote, and the console assumes Intune and Entra. One survivor here is the answer, not a gap.
Why: Documented automatic rollback: SentinelOne one-click on Windows, Sophos CryptoGuard from protected copies / VSS, Kaspersky's Remediation Engine; ESET and Bitdefender and Check Point qualify too.
The trade-off: Rollback has conditions (disk space, Windows-first) and restores files, not the breach. Xcitium's containment is the other bet; Acronis and Seqrite restore from their own backups.
Why: Full EDR telemetry, advanced hunting, forensic timeline and scripted response — the reference agents, and the Microsoft-estate equivalent in P2.
The trade-off: Self-run EDR is a staffing decision: budget analysts or an MDR contract beside the licence. CrowdStrike has no rollback; SentinelOne has no published list.
Why: On-prem consoles (Seqrite, ESET PROTECT On-Prem, GravityZone, Kaspersky Security Center, Check Point, FortiEDR) and India data centres (Seqrite, Acronis Mumbai, SentinelOne and Sophos Mumbai for cloud).
The trade-off: On-prem means you run the console server. If cloud with an India region is acceptable, SentinelOne and Sophos reopen the field; CrowdStrike's India cloud is announced, not yet live.
Why: ESET from $42.20 and Bitdefender from $57 per device per year, Trend Vision One Endpoint Essentials from $2.25 per endpoint per month, Xcitium modular from $2.39 — on the vendors' own pages.
The trade-off: Published entry tiers are prevention-only; EDR costs more at every vendor. Bitdefender's first-year price renews higher — price year two.
Why: NinjaOne deploys and watches a resold Bitdefender / SentinelOne engine from the RMM; Acronis puts backup and EDR in one agent; Hexnode XDR and Scalefusion Veltar add security inside the UEM.
The trade-off: Depth follows the engine: NinjaOne's is real EDR, Acronis recovers by restore, Hexnode XDR is young and Veltar is hardening and access, not an EDR. One console is a convenience; the catch on the card is what you give up.
Why: Xcitium contains unknown files at the kernel so nothing unrecognised runs; Sophos Intercept X Advanced is prevention with rollback; PHASR hardens the attack surface per user before prevention has to fire.
The trade-off: Containment can hold a benign-but-new binary until verdicted; PHASR is an add-on, not a protection engine; none of these is a substitute for someone watching when prevention misses.
Every datasheet says “ransomware protection”. What happens to the encrypted files is where the products genuinely differ — and the mechanism decides what you can promise the board.
Mechanism 1
Protected copy, then restore
Sophos CryptoGuard keeps a temporary copy when a business file is opened for write and restores it if the original is maliciously encrypted (needs ~3 GB free; no rollback if the process is stopped only after encryption completes). ESET's Ransomware Remediation keeps a protected backup store the attacker cannot modify; Check Point Anti-Ransomware restores from its own snapshots.
Mechanism 2
Agent-level rollback
SentinelOne restores encrypted files from its own snapshots on Windows in one action; Bitdefender's Ransomware Mitigation backs up and restores files touched by a detected attack; Kaspersky's Remediation Engine rolls back the malicious actions it recorded.
Mechanism 3
Contain before it runs — or restore from backup
Xcitium's ZeroDwell virtualises unknown files at the kernel so nothing unrecognised touches production — nothing to roll back because nothing executed. Acronis and Seqrite recover by restoring from their own backups: strong, but a restore, not a rollback.
The absence
Isolate, kill, restore from your backups
CrowdStrike, Defender for Endpoint, Cisco and Coro stop the process and isolate the host; files come back from your backup or OneDrive Files Restore, not from the agent. Strong response, no rollback — know which you bought. Trend, FortiEDR, Hexnode and NinjaOne's resold engine are not documented either way here.
Agent coexistence
One real-time engine per machine. Everything else can share.
Who runs it — the four operating models
The licence is the smaller half of every EDR.
Detection quality barely moves with size. Alert volume per analyst, exclusion sprawl and the managed contract’s scope are what move — and they decide whether the EDR tier is real or nominal.
The operating model is the constraint
Put this in your PoC
Run a detection-only week: count alerts, count the ones a human read, count the ones acted on.
Alert volume and exclusions are the constraint
Put this in your PoC
Deploy to a 200-device ring with the RMM and UEM agents present; measure false positives and CPU for a week; read the MDR SLA aloud.
Telemetry, retention and the API are the constraint
Put this in your PoC
Pull 30 days of telemetry through the API; run your three hardest hunts; confirm staged sensor-update control in writing.
CrowdStrike, SentinelOne, Defender, Sophos, Bitdefender, ESET, Trend, Kaspersky, Check Point, Cisco, Fortinet, Acronis and NinjaOne's engines document estates far above 2,000 endpoints; Xcitium, Seqrite, Coro, Hexnode, Scalefusion Veltar and OpenEDR are flagged unverified at that size, not ruled out; Norton is licensed to 20. Where a specific console strains for your estate: [TechBag to confirm].
The agent swap is scriptable through your UEM or RMM. What makes it expensive is the gap: the minutes between old engine off and new engine on, on every machine, and the tamper-protection password nobody remembers.
The agent
Push the new agent first (passive where the vendor supports it), then remove the old with its tamper-protection credential, then activate. Never the other order.
Policies and exclusions
Exclusions for your line-of-business apps, the RMM, the UEM and backup agents are rebuilt by hand. Miss one and the first week is an outage.
Detection history
Alerts, timelines and hunting data stay in the old console. Export what an audit might ask for before the licence ends.
The managed contract
MDR terms run on their own calendar. Overlap two services or end one early — either is a cost line nobody put in the licence comparison.
Cut-over plan and hours for your estate: [TechBag to confirm] — TechBag scopes it from your OS mix, the agents already present and the managed contract dates.
What you may already hold, what the tiers cost in USD and INR, and the part that never appears on the licence line — the people who run it.
Four licences you may hold carry endpoint protection. One of them is usually the answer for a Microsoft estate.
If Defender P2 is already on your invoice, we say so first — and then talk about who will run it.
Published USD with INR for scale; per device per year unless the vendor prices per user per month; the EDR tier named separately from the prevention tier wherever the vendor publishes both. Seqrite’s and Acronis’s INR are the India list.
Term: per device / year; 5-device packs; Elite min 25; MDR on quote.
Term: per device / year, first-year promotional; renewals reported 2–3× higher.
Term: per device / year; breakpoints at 500 / 1,000 / 5,000.
Term: per endpoint / year reseller list — no vendor list; street $48–96 for Complete.
Term: per user / month standalone; $0 marginal inside E3 (P1) / E5 (P2) / Business Premium (DfB).
Term: per endpoint / month; Vision One credits for XDR and add-ons.
Term: per 5 users / year entry; on-prem or cloud console.
Term: per user / year reported — no published list.
Term: per user / month; XDR and hunting tiers quote-only.
Term: per endpoint / year reported; list on quote.
Term: per endpoint / month, modular, postpaid.
Term: per user / year; Sophos publishes no list — estimates only.
Term: per endpoint / year, INR-native through partners, GST invoiced.
Term: per workload / month, India reseller list; cloud or on-prem.
Term: per device / month (Norton per year); engines and depth differ — read the cards.
Term: per user / month; public list removed at the 2026 rebrand.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
An EDR tier without a person is a licence for a dashboard. Price the analyst headcount or the managed service beside the tier — Sophos MDR is reported at $80 ≈ ₹6,640–$200 ≈ ₹16,600 per user per year on top of the agent; CrowdStrike Falcon Complete $25 ≈ ₹2,075–$45 ≈ ₹3,735 per endpoint per month reported. That line is usually larger than the licence.
First-year prices (Bitdefender’s in particular) renew at standard rates; reseller street prices (SentinelOne) move with volume; Microsoft’s E5 moved to $60 in July 2026. Ask for the year-two number in writing before comparing year one.
Tamper-protection credentials, a staged cut-over, exclusion rebuilds and a week of tuning — people-hours, not licence dollars. It sits in the switching-cost section, and the hours for your estate are [TechBag to confirm].
Each of these is documented vendor behaviour; the matching to real TechBag engagements happens before any becomes a named case. They are cheaper to read now than to live through after the contract.
EDR bought, nobody triages it
The console fills; nobody owns it; by month three it is closed. The licence was the cheap half of a purchase that needed a person or a managed contract.
Two real-time engines on one machine
The RMM's security add-on, the UEM's XDR or the backup vendor's AV lands beside the EPP you chose. Both degrade; one blocks the other's updates. Only Defender is designed to step aside.
Assuming EPP covers response
Prevention tiers stop what they recognise and report the rest. When something gets through there is no timeline, no isolation, no hunt — because that was the next tier.
Rollback that doesn't cover what you assumed
Windows-first; needs free disk (Sophos ~3 GB); no rollback if the process was stopped after encryption finished; restores files, not the breach — and absent at CrowdStrike, Defender, Cisco and Coro.
Alert volume makes the console unusable
Untuned EDR at 2,000 endpoints outruns a small team within weeks; tuning and exclusions need an owner. The most common reason an EDR quietly fails.
E3 'includes Defender' — Plan 1, not Plan 2
Prevention only. The EDR is P2, in E5 or E5 Security. A buyer who stops at 'included' has no detection and believes they do.
Tamper protection blocks the migration
The old agent will not uninstall without its credential; the project stalls at machine one. Recover the password before you sign the new contract.
Year-two price shock
Promotional first-year pricing (Bitdefender), reseller street pricing (SentinelOne), credit consumption (Trend) and the July 2026 E5 rise all move at renewal. Compare year-two numbers, tier-matched, or the comparison is fiction.
Vendor-neutral. No gated content.