Prevention stops what it recognises. Detection and response records what got through so a person can find it and act — and without that person, the EDR console is the most expensive dashboard nobody opens.
Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention only. The EDR is Plan 2, and that is in E5. Check the SKU before assuming you own detection.
Already decided — before the detection-rate chart
Still yours to weigh
An agent on every laptop, desktop, server and (usually) phone that does two jobs. The first is prevention: block known malware, exploits and ransomware behaviour before they run — the antivirus lineage, now machine-learning and behaviour-based. The second is detection and response: record process, file, network and identity events continuously, raise what looks wrong, and give a person the tools to investigate and act — isolate the machine, kill the process, roll files back, hunt across the estate.
The first job runs itself. The second does not — it produces alerts, and alerts need someone with time and skill to read them. That is why every vendor on this page also sells people: a managed detection and response service that runs the console for you. Whether you need the second job, and who will do it, decides this purchase more than any detection-rate chart.
The honest cut
EDR without someone to triage it is shelfware with a licence fee. If nobody on your side will open the console daily, buy the managed tier or stay with prevention — and say so in the evaluation, because the vendor’s demo will not.
EPP vs EDR vs XDR vs MDR — the sharpest confusion in the category
EPP prevents. EDR records and lets a person respond. XDR widens the recording to email, identity, cloud and network. MDR is not software — it is the vendor’s or a partner’s analysts running the EDR/XDR for you. Every product here sells the first two as tiers; most sell the fourth as a contract.
EPP vs UEM
UEM configures the device and proves its state; endpoint protection fights what is already on it. One enrols and encrypts; the other isolates and kills. A ransomware scare does not call for a UEM, and an unmanaged-device audit does not call for an EDR — the guides are here for both.
The fuller bench
This page ranks the nine endpoint-protection products carried in this category. TechBag also carries a deeper security bench — it will be ranked under the Security Operations cluster when that ships, and is linked here so nothing is hidden:
Often confused withUEM & MDM — configuring the fleet and proving its state →· RMM & Patch — the agent that deploys and watches your EDR →
The four routes of endpoint management — and which one is yours →
Choose the constraints that are true for you. Products that fail one fade in place with the reason written on them; products we cannot verify for your case are marked and stay in. Every chip is reversible.
Hosting
Commercial shape
Ransomware recovery
Platforms
Who runs it
Fleet size
Prevention-vs-EDR depth removes nothing as a chip — every vendor sells both tiers. It is the operating-capacity question, and it lives in the four-letters section and the reasoning below.
per device / year — Falcon Go (prevention) · Pro · Enterprise (EDR); Falcon Complete MDR on quote
Security teams that will run EDR properly — hunting, timeline, response — and want the reference cloud-native agent.
The catch: No automatic file rollback after ransomware (response is isolate, kill, Real Time Response); Falcon Complete MDR is enterprise-priced on quote; no on-prem console and no documented India data region.
per endpoint / year reseller list (Core · Control · Complete); street lower; Vigilance MDR add-on
Teams that want autonomous detection with a documented one-click rollback, and a Mumbai region for data residency.
The catch: No vendor-published list (reseller listings only; street price varies widely), no on-prem console, and the MDR (Vigilance) is a per-endpoint add-on on top of Complete.
per user / month standalone (P1 / P2); $0 marginal when bundled
Microsoft 365 shops — the EPP/EDR you may already hold, with the tightest Intune and Entra integration there is.
The catch: E3 carries only P1 (no EDR); file rollback is OneDrive Files Restore, not the agent; Defender Experts (managed) needs E5 and a quote; passive-mode coexistence is strong, but the console assumes a Microsoft estate.
per user / year — Advanced · with XDR · MDR (reported ~$48 XDR; MDR from ~$80); Mumbai region
Teams that want the managed service to be the default — Sophos MDR priced for mid-market — with CryptoGuard rollback underneath.
The catch: No published list (estimates only), no on-prem console, and CryptoGuard needs ~3 GB free disk and cannot roll back if the process is stopped after encryption completes.
per device / year — Small Business · Business Security · Premium (EDR); MDR and Enterprise on quote
Price-sensitive mixed fleets wanting published per-device pricing, an on-prem console option and a real EDR tier.
The catch: First-year promotional pricing renews at standard rates (users report 2–3× at renewal); XDR and MDR are quote-only; India cloud region not documented.
per device / year — Entry · Advanced · Complete; Elite (XDR, min 25) and MDR on quote
Lean teams wanting a light agent, published tiers, on-prem or cloud console, and Ransomware Remediation with a protected backup store.
The catch: XDR (ESET Inspect) only arrives at the Elite tier — quote-only, 25-device minimum — so the published prices buy EPP, not EDR; India cloud region not documented.
per endpoint / month, modular and postpaid; OpenEDR free to 50 endpoints
Teams that want unknown files contained at the kernel before they can run — a different bet from detect-then-respond — at modular published prices.
The catch: Containment is the mechanism, not rollback: nothing to restore because nothing ran, but also no file-restore if something is allowed; on-prem option and India region not documented; scale above 2,000 unverified.
per user / year, INR-native through partners (EPS Core → Total); EDR / XDR / MDR on quote
India-regulated estates that need CERT-In-empanelled, INR-billed, India-hosted or on-prem endpoint protection with local support.
The catch: Mobile is a separate product (mSuite), ransomware recovery is restore-from-its-own-backup rather than automatic rollback, and scale above 2,000 endpoints is claimed, not documented.
per user / month, modular (historically ~$7.50–9.50; public list removed at the 2026 rebrand)
SMBs that want endpoint, email, cloud-app and posture in one modular agent with a managed option, and no SOC of their own.
The catch: Linux agent is remote scan-only (no real-time protection), no documented file rollback, no on-prem, public pricing withdrawn in 2026, and scale above 2,000 endpoints unverified.
On-prem management consoleRules out CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X and Coro Endpoint & EDR — cloud-only console. That leaves Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection. It flags Xcitium (ZeroDwell) — On-prem option not documented either way — marked on the cards, not removed.
Vendor-published list priceRules out SentinelOne Singularity Endpoint, Sophos Intercept X, Seqrite Endpoint Protection and Coro Endpoint & EDR — quote-only (reseller listings at most). That leaves CrowdStrike Falcon, Microsoft Defender for Endpoint, Bitdefender GravityZone, ESET PROTECT and Xcitium (ZeroDwell).
Automatic file rollback after ransomwareRules out CrowdStrike Falcon, Microsoft Defender for Endpoint and Coro Endpoint & EDR — no documented automatic file rollback (response is isolate, kill, restore from your own backups). That leaves SentinelOne Singularity Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection. It flags Xcitium (ZeroDwell) — Prevents by containing unknown files before they run and Seqrite Endpoint Protection — Restores from its own ransomware backup rather than automatic rollback — marked on the cards, not removed.
Linux servers with real-time protectionRules out Coro Endpoint & EDR — Linux agent is remote scan-only, no real-time protection. That leaves CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection.
Phones and tablets in the same consoleRules out Seqrite Endpoint Protection — mobile is a separate product (Seqrite mSuite). That leaves CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Coro Endpoint & EDR.
Nobody to triage alertsRules nothing out on published terms. It flags CrowdStrike Falcon — Managed tier is enterprise-gated (quote / E5) and Microsoft Defender for Endpoint — Managed tier is enterprise-gated (quote / E5) — marked on the cards, not removed.
Above 2,000 endpointsRules nothing out on published terms. It flags Xcitium (ZeroDwell) — Unverified above 2,000 endpoints, Seqrite Endpoint Protection — Unverified above 2,000 endpoints and Coro Endpoint & EDR — Unverified above 2,000 endpoints — marked on the cards, not removed.
Prevention only, or full EDRRules nothing out on SKU lines: every vendor here sells a prevention-only tier and an EDR tier (Falcon Go → Enterprise; Singularity Core → Complete; Defender P1 → P2; Intercept X Advanced → with XDR; GravityZone Business → Premium; ESET Entry → Elite; Seqrite EPS → EDR; Xcitium and Coro by module). The cut is not which product — it is which tier, and whether anyone will open the EDR console. That is the operating-capacity question above.
India data residency in the cloudDocumented: SentinelOne (Mumbai), Sophos Central (Mumbai) and Seqrite (India data centres, on-prem). Not documented either way for the rest — so no chip, and no product is ruled out on it. Ask for the region in writing before you sign.
Coexisting with the agents you already runRules nothing out, but decides the rollout: on Windows, Microsoft Defender Antivirus drops to passive mode automatically when another engine registers, so a third-party EPP coexists with Defender for Endpoint's EDR telemetry; two third-party real-time engines do not coexist. RMMs (NinjaOne, Atera, TeamViewer, Splashtop) resell or integrate several of these — which means a second engine arrives unannounced if you are not watching.
Under 50 endpointsRules nothing out on published minimums — Xcitium OpenEDR is free to 50, ESET starts at 5 devices (Elite at 25), Defender for Business is sized to 300 users, Bitdefender and CrowdStrike Falcon Go sell in small packs. Which enterprise-tier SKUs are a poor fit at this size is delivery-team judgement: [TechBag to confirm].
Each shortlist states who will run it. If the answer is nobody, the shortlist changes — that is the point.
Why: Managed detection priced for mid-market, sold with the agent by the same vendor; Sophos leads with MDR as the default product, Bitdefender and ESET sell MDR on top of published tiers.
The trade-off: MDR scope is endpoint-first — identity, email and cloud are separate services — and the contract, not the agent, is what you are buying. Coro is the all-in-one alternative if email and posture matter more than depth.
Why: Defender for Endpoint P2 is already paid for; buying a second EDR duplicates it. On E3 you hold only P1 — prevention, no EDR — so the question becomes E5 Security versus a third-party EDR.
The trade-off: No file rollback in the agent, managed (Defender Experts) is a quote, and the console assumes Intune and Entra. One survivor here is the right answer, not a gap.
Why: Documented automatic rollback: SentinelOne (one-click, Windows), Sophos CryptoGuard (protected copies / VSS), ESET Ransomware Remediation (protected backup store). Bitdefender's Ransomware Mitigation qualifies too.
The trade-off: Rollback has limits — disk space (Sophos ~3 GB), Windows-first, and it restores files, not the breach. Xcitium's containment is the other bet: nothing to roll back because nothing ran.
Why: Full EDR telemetry, advanced hunting, forensic timeline and scripted response; CrowdStrike and SentinelOne are the reference agents, Defender P2 is the Microsoft-estate equivalent.
The trade-off: Self-run EDR is a staffing decision: budget analysts or an MDR contract beside the licence. CrowdStrike has no file rollback; SentinelOne has no published list.
Why: On-prem consoles (Seqrite, ESET PROTECT On-Prem, GravityZone virtual appliance), and Seqrite's India data centres with CERT-In empanelment and INR billing.
The trade-off: On-prem means you run the console server. If cloud with an India region is acceptable, SentinelOne (Mumbai) and Sophos Central (Mumbai) reopen the field.
Why: ESET from $42.20 and Bitdefender from $57 per device per year on the vendors' own pages; Xcitium modular from $2.39 per endpoint per month and OpenEDR free to 50.
The trade-off: Published entry tiers are prevention-only; EDR costs more at every vendor (ESET's is Elite, quote). Bitdefender's first-year price renews higher — price the renewal, not the promotion.
Why: Coro's modular single agent covers endpoint, email, cloud-app and device posture with a managed option; Sophos Central and ESET PROTECT Complete bundle email and endpoint under one console.
The trade-off: Breadth over depth: Coro's Linux agent is scan-only and public pricing is gone; Sophos and ESET go deeper on the endpoint and lighter on the rest.
Why: Defender coexists natively (passive mode, EDR block mode) with whatever the UEM pushes; Xcitium documents EDR-on-top-of-Defender; SentinelOne, CrowdStrike and Bitdefender are the engines the RMMs (NinjaOne, Atera) deploy and watch.
The trade-off: Three agents is normal; two real-time engines is the failure. Document exclusions both ways and make the RMM deploy the EDR agent, never manage it.
The same vendor sells all four. They are priced, staffed and audited differently — and the tier you sign is the one you operate, not the one in the demo.
EPP
Prevention
Blocks known malware, exploit techniques and ransomware behaviour at the endpoint. Runs itself; the console is for policy and reporting. Every vendor’s entry tier.
EDR
Detection & response
Continuous recording of process, file, network and identity events; alerts; a console to investigate, isolate, kill, hunt and — at some vendors — roll files back. Produces work.
XDR
Extended telemetry
EDR’s recording joined with email, identity, cloud and network signals so one incident is one story. More to see; more to staff. Useful when the other sources exist and someone correlates them.
MDR
People, not software
The vendor or a partner runs the EDR/XDR 24/7: triage, investigation, containment, a call at 3am. Scope is written in the contract — endpoint-first, often not identity or email, response means contain, rarely rebuild.
Protected copy, then restore
Sophos CryptoGuard keeps a temporary copy when a business file is opened for write and restores it if the original is maliciously encrypted — from its copies or VSS; needs ~3 GB free and cannot act if the process is stopped only after encryption completes. ESET’s Ransomware Remediation keeps a protected backup store the attacker cannot modify (2-week retention by default).
Agent-level one-click rollback
SentinelOne restores encrypted files from its own snapshots on Windows in one action from the console; Bitdefender’s Ransomware Mitigation backs up and restores files touched by a detected attack.
Contain before it runs
Xcitium’s ZeroDwell virtualises unknown files at the kernel so nothing unrecognised touches production — there is nothing to roll back because nothing executed. The trade: a genuinely new-but-safe binary runs contained until verdicted.
Isolate, kill, restore from your backups
CrowdStrike, Defender for Endpoint and Coro stop the process and isolate the host; files come back from your backup or OneDrive Files Restore, not from the agent. Seqrite restores from its own ransomware backup. Strong response, no rollback — know which you bought.
Agent coexistence
One real-time engine per machine. Everything else can share.
Who runs it — the four operating models
Detection quality barely moves with size. Alert volume per analyst, exclusion sprawl and the managed contract’s scope are what move — and they decide whether the EDR tier is real or nominal.
The operating model is the constraint
Put this in your PoC
Run a detection-only week: count alerts, count the ones a human read, count the ones acted on.
Alert volume and exclusions are the constraint
Put this in your PoC
Deploy to a 200-device ring with the RMM and UEM agents present; measure false positives and CPU for a week; read the MDR SLA aloud.
Telemetry, retention and the API are the constraint
Put this in your PoC
Pull 30 days of telemetry through the API; run your three hardest hunts; confirm staged sensor-update control in writing.
CrowdStrike, SentinelOne, Defender, Sophos, Bitdefender and ESET document estates far above 2,000 endpoints; Xcitium, Seqrite and Coro are flagged unverified at that size, not ruled out. At what size a given console starts to strain for your estate is delivery-team experience: [TechBag to confirm].
The agent swap is scriptable through your UEM or RMM. What makes it expensive is the gap: the minutes between old engine off and new engine on, on every machine, and the tamper-protection password nobody remembers.
The agent
Push the new agent first (passive where the vendor supports it), then remove the old with its tamper-protection credential, then activate. Never the other order.
Policies and exclusions
Exclusions for your line-of-business apps, the RMM, the UEM and backup agents are rebuilt by hand. Miss one and the first week is an outage.
Detection history
Alerts, timelines and hunting data stay in the old console. Export what an audit might ask for before the licence ends.
The managed contract
MDR terms run on their own calendar. Overlap two services or end one early — either is a cost line nobody put in the licence comparison.
Cut-over plan and hours for your estate: [TechBag to confirm] — TechBag scopes it from your OS mix, the agents already present and the managed contract dates.
What you may already hold, what the tiers cost in USD and INR, and the part that never appears on the licence line — the people who run it.
Three licences you may hold carry endpoint protection. One of them is usually the answer for a Microsoft estate.
If Defender P2 is already on your invoice, we say so first — and then talk about who will run it.
Published USD with INR at ≈₹83/$ for scale; per device per year unless the vendor prices per user per month; the EDR tier named separately from the prevention tier wherever the vendor publishes both. Seqrite’s INR is the list and the USD is the conversion.
Term: per device / year; 5-device packs; Elite min 25; MDR on quote.
Term: per device / year, first-year promotional; renewals reported 2–3× higher.
Term: per device / year; breakpoints at 500 / 1,000 / 5,000.
Term: per endpoint / year reseller list — no vendor list; street commonly $48–96 for Complete.
Term: per user / month standalone; $0 marginal inside E3 (P1) / E5 (P2) / Business Premium (DfB).
Term: per endpoint / month, modular, postpaid, no long-term contract.
Term: per user / year; Sophos publishes no list — estimates only.
Term: per user / year, INR-native through partners, GST invoiced.
Term: per user / month; public list removed at the 2026 rebrand.
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale; the tier-matched INR quote — with the EDR tier and the managed contract priced as one line — is ours.
An EDR tier without a person is a licence for a dashboard. Price the analyst headcount or the managed service beside the tier — Sophos MDR is reported at $80 ≈ ₹6,640–$200 ≈ ₹16,600 per user per year on top of the agent; CrowdStrike Falcon Complete and Defender Experts are quotes. That line is usually larger than the licence.
First-year prices (Bitdefender’s in particular) renew at standard rates; reseller street prices (SentinelOne) move with volume; Microsoft’s E5 moved to $60 in July 2026. Ask for the year-two number in writing before comparing year one.
Tamper-protection credentials, a staged cut-over, exclusion rebuilds and a week of tuning — people-hours, not licence dollars. It sits in the switching-cost section, and the hours for your estate are [TechBag to confirm].
Each of these is documented vendor behaviour; the matching to real TechBag engagements happens before any becomes a named case. They are cheaper to read now than to live through after the contract.
EDR bought, nobody triages it
The console fills; nobody owns it; by month three it is closed. The licence was the cheap half of a purchase that needed a person or a managed contract.
Two real-time engines on one machine
The RMM’s security add-on or the UEM’s bundled AV lands beside the EPP you chose. Both degrade; one blocks the other’s updates. Only Defender is designed to step aside.
Assuming EPP covers response
Prevention tiers stop what they recognise and report the rest. When something gets through there is no timeline, no isolation, no hunt — because that was the next tier.
MDR scope narrower than expected
The contract covers endpoints; the incident started in email or identity. ‘Response’ meant contain the host, not rebuild it. Read the scope line before the incident, not during.
E3 ‘includes Defender’ — Plan 1, not Plan 2
Prevention only. The EDR is P2, in E5 or E5 Security. A buyer who stops at ‘included’ has no detection and believes they do.
Tamper protection blocks the migration
The old agent will not uninstall without its credential; the project stalls at machine one. Recover the password before you sign the new contract.
Rollback has conditions
Windows-first; needs free disk (Sophos ~3 GB); no rollback if the process was stopped after encryption finished. It restores files, not the breach — and it is absent at CrowdStrike, Defender and Coro.
Year-two price shock
Promotional first-year pricing (Bitdefender), reseller street pricing (SentinelOne) and the July 2026 E5 rise all move at renewal. Compare year-two numbers, tier-matched, or the comparison is fiction.
Vendor-neutral. No gated content.