EPP and EDR answer different questions. Most buyers purchase one believing they bought both.

Prevention stops what it recognises. Detection and response records what got through so a person can find it and act — and without that person, the EDR console is the most expensive dashboard nobody opens.

Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention only. The EDR is Plan 2, and that is in E5. Check the SKU before assuming you own detection.

Already decided — before the detection-rate chart

Who will triage alertsset by headcount, before any demo
Microsoft 365 tier you holdE3 is P1; E5 is P2
Agents already on the machineUEM, RMM, backup — one real-time engine

Still yours to weigh

Prevention or responseEPP tier, or EDR tier
Rollback or containmenthow you get files back
Managed, or run it yourselfthe contract is the larger half
If you’ve never bought one

What endpoint protection actually is

An agent on every laptop, desktop, server and (usually) phone that does two jobs. The first is prevention: block known malware, exploit techniques and ransomware behaviour before they run — the antivirus lineage, now machine-learning and behaviour-based. The second is detection and response: record process, file, network and identity events continuously, raise what looks wrong, and give a person the tools to investigate and act — isolate the machine, kill the process, roll files back, hunt across the estate.

The first job runs itself. The second does not — it produces alerts, and alerts need someone with time and skill to read them. That is why every vendor on this page also sells people: a managed detection and response service that runs the console for you (its own guide is here). Whether you need the second job, and who will do it, decides this purchase more than any detection-rate chart.

The honest cut

EDR without someone to triage it is shelfware with a licence fee. If nobody on your side will open the console daily, buy the managed tier or stay with prevention — and say so in the evaluation, because the vendor’s demo will not.

Often confused withManaged Detection & Response — a tool, versus someone to run it·UEM & MDM — configuring and proving the fleet, not fighting what's on it·Vulnerability Management — what could be attacked, versus what is being attacked·Cyber Recovery — where ransomware prevention meets ransomware recovery

The six routes of security — and which one is yours

Boundary — the terms this buyer confuses

EPP · EDR · XDR — and why they aren’t a quality ladder

Three letters that every vendor sells as tiers. They are not better-worse; they are narrower-wider. Each one widens the scope of what is recorded — and each widening costs more and needs more people to read what it records.

EPP — Endpoint Protection Platform

Prevention at the endpoint: block known malware, exploit techniques and ransomware behaviour before they run. The console is for policy and reporting; it runs itself. Every vendor's entry tier. Broad enough for many estates under ~300 seats that accept nothing is hunting.

EDR — Endpoint Detection & Response

Continuous recording of process, file, network and identity events on the endpoint, alerts on what looks wrong, and a console to investigate, isolate, kill, hunt — and at some vendors roll files back. It produces work for a person every day. Not 'better EPP'; a different job that assumes EPP missed something.

XDR — Extended Detection & Response

EDR's recording joined with email, identity, cloud and network signals so one incident is one story. Wider scope again — more to see, more to staff, and worth it only when those other sources exist and someone correlates them. Platform vendors sell it as the reason to buy everything from them.

These are widening scopes, not tiers of quality. A good EPP is not a worse EDR; an XDR is not the best EPP. Broader records more, costs more, and needs more people to run it. Buy the scope someone on your side will operate — and if that is nobody, the next guide (MDR) is the one you need.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase — the instrument tests the ones documentation can verify; the rest are prose because the honest answer depends on your team.

01

Prevention depth vs detection-and-response depth

Which job you are buying — the entry tier blocks, the higher tier records and lets a person respond. Every vendor sells both; the price gap is the second job.

02

Who operates it

The honest cut. An EDR with no one to triage it is shelfware — so the chip asks whether the vendor sells the people too, and whether that managed tier is priced for you or enterprise-gated.

03

Agent coexistence

What is already on the machine: UEM, RMM, backup, an old AV. One real-time engine per machine; Windows steps Defender aside automatically; two third-party engines do not coexist.

04

Rollback and remediation

Four mechanisms and one absence — protected-copy restore, agent-level rollback, containment, restore-from-backup, or isolate-and-kill only. Know which you bought before the first incident.

05

Managed option availability

Whether the vendor's own 24/7 service exists for this SKU, what it covers, and what it costs — the MDR guide takes it from here.

06

Platform bundling vs best-of-breed

One suite (Microsoft, Sophos, Trend, Kaspersky, Bitdefender, ESET) or the best agent most consoles integrate (CrowdStrike, SentinelOne) — and the UEM / RMM / backup vendors selling security inside their console. Convenience versus depth; the card's limitation tells you the price.

07

India data residency

Documented for SentinelOne and Sophos (Mumbai), Seqrite, Acronis, Scalefusion; announced for CrowdStrike; unknown for most. The instrument never eliminates on 'unknown' — it flags and you ask in writing.

The narrowing instrument · the reasoning is the product

Narrow 35 products to your shortlist

Choose the constraints that are true for you. Products that fail one fade in place with the reason written on them; products we cannot verify for your case are marked and stay in. Every chip is reversible; nothing leaves the page.

Hosting

Prevention or response

Commercial shape

Platforms

Ransomware recovery

Who runs it

Fleet size

India data residency, platform bundling and agent coexistence remove nothing as chips — their reasoning is in the notes below and in the four-letters section. Prevention vs EDR is the one cut every vendor's price list makes.

Still in35/ 35
CrowdStrike logo
$59.99–99.99₹4,979

per device / year — Falcon Go (prevention) · Pro; the reference cloud-native agent

Teams that want CrowdStrike's prevention agent today and a path to Insight EDR tomorrow without a second install.

The catch: Prevention only — no timeline, hunting or response until you add Insight; no file rollback; India in-country cloud is announced, not yet documented live.

Prevention tierPublished listCloud-only
Intel page →
CrowdStrike logo
$184.99₹15,354

per device / year (Falcon Enterprise bundle with Prevent); Falcon Complete MDR on quote

Security teams that will hunt — the reference EDR telemetry, forensic timeline and Real Time Response.

The catch: An EDR that needs operators: no automatic file rollback, Falcon Complete (managed) is enterprise-priced on quote, and the bundle is the cloud-only Falcon platform.

EDR referencePublished listCloud-only
Intel page →
SentinelOne logo
~$70–180₹5,809

per endpoint / year reseller list (Core · Control · Complete); Vigilance MDR add-on; Mumbai region

Autonomous prevention-to-response on one agent with documented one-click rollback and an India data region.

The catch: No vendor-published list (street price varies widely), no on-prem console; mobile is a paid Singularity Mobile add-on.

File rollbackIndia region (Mumbai)Cloud-only
Intel page →
Microsoft logo
$3 / $5.20₹249

per user / month standalone (P1 prevention / P2 EDR); $0 marginal when bundled

Microsoft 365 estates — the EPP/EDR you may already hold, with the tightest Intune and Entra integration there is.

The catch: E3 carries only P1 (no EDR); file rollback is OneDrive Files Restore, not the agent; Defender Experts (managed) needs E5 and a quote; the console assumes a Microsoft estate.

P1 in M365 E3 · P2 in E5 / E5 Security · Defender for Business in Business PremiumIn a bundle you may ownPublished listCloud-only
Intel page →
Sophos logo

per user / year (reported ~$30–50); Sophos Central; Mumbai region

Prevention with CryptoGuard file rollback for teams that want Sophos MDR to be the default operating model later.

The catch: The Advanced SKU is prevention — detection and response is the separate 'with XDR' tier; no published list; CryptoGuard rollback needs ~3 GB free disk.

File rollbackIndia region (Mumbai)Prevention tier
Intel page →
Sophos logo

per user / year (reported ~$48); adds XDR data lake, cross-product detections; Mumbai region

Teams that want EDR/XDR on the Sophos agent with the MDR tier one step away.

The catch: Estimates only — no published list; XDR breadth across email / firewall / cloud is a Sophos-estate story; no on-prem console.

File rollbackXDRIndia region (Mumbai)
Intel page →
Bitdefender logo
$57–74₹4,731

per device / year — Small Business · Business Security (EPP); Premium adds EDR

Price-sensitive mixed fleets wanting published per-device prevention with Ransomware Mitigation and an on-prem console option.

The catch: Prevention tier — EDR is the Premium SKU; first-year promotional pricing renews at standard rates (users report 2–3×); India cloud region not documented.

File rollbackPublished listOn-prem console
Intel page →
Bitdefender logo

per device / year (Business Security Premium with EDR); XDR / Enterprise on quote

Bitdefender prevention plus a real EDR tier, with MDR available from the same vendor.

The catch: XDR and Enterprise are quote-only; the published Premium price is first-year promotional; India region not documented.

File rollbackEDROn-prem console
Intel page →
Bitdefender logo

add-on to GravityZone — proactive hardening and attack-surface reduction per user behaviour

GravityZone estates that want the attack surface tailored per user before prevention ever has to fire.

The catch: An add-on, not standalone protection — it hardens, it does not detect or roll back; quote-only.

Add-onHardening
Intel page →
ESET logo
$42.20₹3,503

per device / year (5-device packs); endpoint + file-server protection

Lean teams wanting a light agent, published pricing, on-prem or cloud console and Ransomware Remediation.

The catch: Prevention only — no EDR (Elite), no mobile (Advanced+), no sandbox; ESET MDR is a separate quote.

Published listOn-prem consoleFile rollback
Intel page →
ESET logo
$55₹4,565

per device / year; adds cloud sandbox, full-disk encryption, Mobile Threat Defense

ESET Entry plus sandboxing, encryption and phones in the same console.

The catch: Still prevention — EDR arrives only at Elite (quote, 25-device minimum); India cloud region not documented.

Published listMobile in consoleFile rollback
Intel page →
ESET logo
$57.54₹4,776

per device / year; adds Microsoft 365 / Google Workspace protection, mail server, vulnerability & patch

One ESET console for endpoint, mail and patching in a small estate.

The catch: Breadth without EDR — detection and response is the Elite tier; the M365 / Workspace protection is email filtering, not an EDR for mail.

Published listMail + patch bundledFile rollback
Intel page →
ESET logo

per device / year, 25-device minimum; adds ESET Inspect (XDR) and MFA

ESET estates that outgrew prevention and want the XDR tier and ESET MDR on the same agent.

The catch: Quote-only with a 25-device minimum; ESET Inspect is an operator's console — budget the analyst or the MDR.

XDROn-prem consoleQuote-only
Intel page →
Trend Micro logo
$2.25–14.92₹187

per endpoint / month — Essentials · Standard · Advanced; Apex One on-prem still sold

Estates that want Trend's endpoint sensor feeding Vision One XDR, with Service One MDR from the same vendor.

The catch: Advanced is the EDR-grade tier at ~6× Essentials; credit-based Vision One billing is hard to forecast; automatic file rollback is not documented.

Published listOn-prem optionXDR platform
Intel page →
Trend Micro logo
Credits

Vision One credits, annual; correlates endpoint, email, network, cloud, identity

Trend estates correlating endpoint with email, network and cloud telemetry in one platform.

The catch: Needs Trend sensors to be worth it; credit consumption is opaque until you run it; no published list.

XDRCredit-basedCloud-only
Intel page →
Kaspersky logo

per 5 users / year (Foundations); Optimum / Expert and MXDR on quote; on-prem or cloud console

Estates wanting a full prevention-to-EDR ladder with the Remediation Engine rollback and an MXDR option on the same agent.

The catch: Procurement-sensitive in some sectors and countries (US ban; check your regulator); EDR Expert is enterprise-priced; India data region not documented.

File rollbackOn-prem consoleMobile in console
Intel page →
Kaspersky logo

per user / year, cloud console; Pro / Plus tiers add EDR Optimum-grade features

Small estates wanting Kaspersky prevention with phones included and nothing to host.

The catch: Prevention-first — full EDR is the Next line; cloud-only; the same procurement caveats as Kaspersky Next.

Cloud-onlyMobile in consoleFile rollback
Intel page →
Seqrite logo

per endpoint / year, INR-native (EPS Core → Total); EDR / XDR on quote

India-regulated estates that need CERT-In-empanelled, INR-billed, on-prem endpoint protection with local support.

The catch: Prevention tier — EDR/XDR are separate SKUs; mobile is mSuite (separate console); ransomware recovery restores from its own backup rather than rolling back; scale above 2,000 claimed, not documented.

India-builtOn-premINR list
Intel page →
Seqrite logo

per endpoint / year, INR-native, India-hosted cloud console

The same Seqrite protection with nothing to host and data in India.

The catch: Cloud-only variant of a prevention tier; EDR/XDR are add-ons; scale above 2,000 endpoints not documented.

India-builtIndia DCCloud
Intel page →
Seqrite logo
Quote

add-on per endpoint / year (≈ ₹350 over EPS Core reported); INR-native

Seqrite estates adding detection and response without leaving the India-hosted stack.

The catch: An add-on to EPS, not standalone; quote-only; depth of hunting and telemetry retention is not documented at the level CrowdStrike or SentinelOne publish.

India-builtEDR add-on
Intel page →
Seqrite logo

per endpoint / year, INR-native; correlates Seqrite endpoint, network and cloud telemetry

India estates wanting XDR and MDR from one CERT-In-empanelled vendor.

The catch: XDR breadth is Seqrite-stack-first; quote-only; unverified above 2,000 endpoints.

India-builtXDR
Intel page →
Xcitium logo
$2.39₹198

per endpoint / month, modular and postpaid; OpenEDR free to 50 endpoints

Teams that want unknown files contained at the kernel before they run — a different bet from detect-then-respond.

The catch: Containment is the mechanism, not rollback — nothing to restore because nothing ran, and no file-restore if something is allowed; on-prem and India region not documented.

ContainmentPublished listModular
Intel page →
Xcitium logo
Modular

per endpoint / month module; runs beside Microsoft Defender (documented)

An EDR module that can sit on top of Defender AV or the Xcitium stack.

The catch: Module pricing adds up; unverified above 2,000 endpoints; India region not documented.

EDRWorks with Defender
Intel page →
Xcitium logo
Modular

per endpoint / month module; network, cloud and endpoint telemetry

Xcitium estates widening the recording beyond the endpoint.

The catch: XDR depth is Xcitium-stack-first; scale and region unverified.

XDRModular
Intel page →
Xcitium logo
Free₹0

open-source EDR, free to 50 endpoints; paid platform beyond

Teams that want real EDR telemetry for nothing, and will run it themselves.

The catch: Windows-only, EDR-only (no prevention engine), nobody watches it but you — shelfware unless someone reads the console daily.

Free forever — up to 50 endpoints (open source)FreeOpen sourceWindows-only
Intel page →
Check Point logo
~$25–45₹2,075

per user / year reported (Basic · Advanced · Complete); on-prem or Infinity cloud management

Check Point estates wanting prevention-first endpoint with anti-ransomware restore and Infinity-portal management.

The catch: No published list (reported ranges only); managed service is enterprise-gated; India data region not documented.

File rollbackOn-prem consoleInfinity platform
Intel page →
Cisco logo
$6.75₹560

per user / month (Essentials); Advantage / Premier (XDR, hunting) on quote; private-cloud appliance option

Cisco-network estates wanting endpoint telemetry that joins Umbrella, Secure Firewall and Cisco XDR.

The catch: Only Essentials is published; the XDR and hunting tiers are quote-only; file rollback not documented; mobile not covered.

Published entryOn-prem optionCisco stack
Intel page →
Cisco logo
~$69₹5,727

per user / year reported (Essentials · Advantage · Premier); correlates Cisco and third-party telemetry

Cisco estates correlating endpoint, network, email and identity in one console.

The catch: Needs sources to correlate — alone it is a console; quote-only; no rollback; cloud-only.

XDRCloud-onlyQuote-only
Intel page →
Fortinet logo
~$20–35₹1,660

per endpoint / year reported; on-prem or cloud; FortiGuard MDR option

Fortinet Security Fabric estates wanting pre- and post-infection protection with an MDR option on the same agent.

The catch: No published list; automatic file rollback not documented; no mobile coverage; strongest inside a Fortinet stack.

On-prem optionSecurity FabricMDR option
Intel page →
Acronis logo

per workload / month (Advanced with EDR, India reseller list); cloud or on-prem; Mumbai data centre

Estates that want backup and EDR in one agent — recovery is a restore, not a rollback.

The catch: Recovery means restoring from Acronis backup (strong, but not automatic rollback); EDR depth is below the pure-play leaders; per-workload pricing climbs with servers.

Backup + EDRIndia DCOn-prem option
Intel page →
Coro logo

per user / month, modular (historically ~$7.50–10.50); managed SOC option

SMBs that want endpoint, email, cloud-app and posture in one modular agent with a managed option.

The catch: Linux agent is remote scan-only; no documented file rollback; public list withdrawn in 2026; unverified above 2,000 endpoints.

SMB-firstModularCloud-only
Intel page →
Norton logo
$179.99₹14,939

per year for 10 devices (first year; Premium $299.99); up to 20 devices

Very small businesses that want consumer-grade antivirus with a business licence and nothing to manage.

The catch: Licensed for up to 20 devices — not an enterprise product; no EDR, no Linux, no console for compliance evidence, no managed option.

Published listUp to 20 devicesConsumer lineage
Intel page →
Hexnode logo
$5.50₹457

per device / month; UEM-native endpoint security inside the Hexnode console

Hexnode UEM estates that want threat protection in the console they already run.

The catch: A young product from a UEM vendor — EDR depth, Linux coverage and rollback are not documented; no managed service; unverified at scale.

UEM-adjacentPublished listYoung product
Intel page →
Scalefusion logo
~$3–4₹249

per device / month reported; UEM-native: web filtering, DLP, VPN/ZTNA, compliance

Scalefusion UEM estates adding web filtering, DLP and zero-trust access from the same India-hosted console.

The catch: Not an anti-malware engine — no detection and response, no rollback; a hardening and access layer beside your EPP, not instead of it.

UEM-adjacentIndia-hostedNot an AV/EDR
Intel page →
NinjaOne logo

per endpoint / month reported, on top of the NinjaOne RMM seat; resold Bitdefender or SentinelOne engine

NinjaOne RMM estates that want the EDR engine deployed and watched from the RMM console.

The catch: You buy the RMM first; the engine is Bitdefender or SentinelOne with their capabilities — rollback and managed options depend on which; NinjaOne regions are US/EU/CA/OC, no India.

RMM-adjacentResold engineNo India region
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

On-prem management consoleRules out CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Trend Vision One XDR, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection Cloud, Cisco XDR, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — cloud-only console. That leaves Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite Endpoint Protection (on-prem), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR and Acronis Cyber Protect (EDR). It flags Xcitium ZeroDwell (containment) — On-prem option not documented either way, Xcitium EDR — On-prem option not documented either way and Xcitium XDR — On-prem option not documented either way — marked on the cards, not removed.

Full EDRRules out CrowdStrike Falcon Prevent (Go / Pro), Sophos Intercept X Advanced, Bitdefender GravityZone Business Security, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Norton Small Business and Hexnode XDR — a prevention-tier SKU; EDR is a higher tier or a separate product; Bitdefender GravityZone PHASR and Scalefusion Veltar — a hardening / access add-on, not detection and response. That leaves CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne).

Prevention only is enoughRules out CrowdStrike Falcon Insight XDR, Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR and Cisco XDR — an EDR / XDR SKU that needs operators and a prevention engine beside it; Bitdefender GravityZone PHASR and Scalefusion Veltar — an add-on that needs a protection engine beside it. That leaves CrowdStrike Falcon Prevent (Go / Pro), SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne).

Vendor-published list priceRules out SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone PHASR, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One XDR, Seqrite EDR, Seqrite XDR (HawkkHunt), Check Point Harmony Endpoint, Cisco XDR, Fortinet FortiEDR, Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — quote-only (reported ranges at most). That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, Trend Vision One Endpoint Security, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Cisco Secure Endpoint, Acronis Cyber Protect (EDR), Norton Small Business, Hexnode XDR and Scalefusion Veltar.

Linux servers with real-time protectionRules out Xcitium OpenEDR and Norton Small Business — no Linux coverage; Coro Endpoint & EDR — Linux agent is scan-only, no real-time protection. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Linux coverage not documented, Hexnode XDR — Linux coverage not documented and Scalefusion Veltar — Linux coverage not documented — marked on the cards, not removed.

Phones and tablets in the same consoleRules out Bitdefender GravityZone PHASR, ESET PROTECT Entry, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium OpenEDR, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR) and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — no mobile coverage in this SKU. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Coro Endpoint & EDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar. It flags CrowdStrike Falcon Prevent (Go / Pro) — Mobile is a paid add-on to the same console, CrowdStrike Falcon Insight XDR — Mobile is a paid add-on to the same console, SentinelOne Singularity Endpoint — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced — Mobile is a paid add-on to the same console, Sophos Intercept X Advanced with XDR — Mobile is a paid add-on to the same console, Bitdefender GravityZone Business Security — Mobile is a paid add-on to the same console, Bitdefender GravityZone EDR / XDR (Premium · Enterprise) — Mobile is a paid add-on to the same console, Trend Vision One Endpoint Security — Mobile is a paid add-on to the same console, Trend Vision One XDR — Mobile is a paid add-on to the same console and Check Point Harmony Endpoint — Mobile is a paid add-on to the same console — marked on the cards, not removed.

Automatic file rollbackRules out CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, Microsoft Defender for Endpoint P1 / P2, Cisco XDR, Coro Endpoint & EDR, Norton Small Business and Scalefusion Veltar — no documented automatic file rollback (response is isolate, kill, restore from your own backups). That leaves SentinelOne Singularity Endpoint, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Hexnode XDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Bitdefender GravityZone PHASR — Rollback not documented either way, Trend Vision One Endpoint Security — Rollback not documented either way, Trend Vision One XDR — Rollback not documented either way, Seqrite Endpoint Protection (on-prem) — Restores from its own backup rather than automatic rollback, Seqrite Endpoint Protection Cloud — Restores from its own backup rather than automatic rollback, Seqrite EDR — Restores from its own backup rather than automatic rollback, Seqrite XDR (HawkkHunt) — Restores from its own backup rather than automatic rollback, Xcitium ZeroDwell (containment) — Prevents by containing unknown files before they run, Xcitium EDR — Prevents by containing unknown files before they run, Xcitium XDR — Prevents by containing unknown files before they run, Xcitium OpenEDR — Rollback not documented either way, Cisco Secure Endpoint — Rollback not documented either way, Fortinet FortiEDR — Rollback not documented either way, Acronis Cyber Protect (EDR) — Restores from its own backup rather than automatic rollback, Hexnode XDR — Rollback not documented either way and NinjaOne Endpoint Security (Bitdefender / SentinelOne) — Rollback not documented either way — marked on the cards, not removed.

Nobody to triage alertsRules out Xcitium OpenEDR, Norton Small Business, Hexnode XDR and Scalefusion Veltar — no managed detection service from the vendor. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags CrowdStrike Falcon Prevent (Go / Pro) — Managed tier is enterprise-gated (quote / E5), CrowdStrike Falcon Insight XDR — Managed tier is enterprise-gated (quote / E5), Microsoft Defender for Endpoint P1 / P2 — Managed tier is enterprise-gated (quote / E5), Check Point Harmony Endpoint — Managed tier is enterprise-gated (quote / E5), Cisco Secure Endpoint — Managed tier is enterprise-gated (quote / E5) and Cisco XDR — Managed tier is enterprise-gated (quote / E5) — marked on the cards, not removed.

Above 2,000 endpointsRules out Norton Small Business — licensed for up to 20 devices. That leaves CrowdStrike Falcon Prevent (Go / Pro), CrowdStrike Falcon Insight XDR, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint P1 / P2, Sophos Intercept X Advanced, Sophos Intercept X Advanced with XDR, Bitdefender GravityZone Business Security, Bitdefender GravityZone EDR / XDR (Premium · Enterprise), Bitdefender GravityZone PHASR, ESET PROTECT Entry, ESET PROTECT Advanced, ESET PROTECT Complete, ESET PROTECT Elite (ESET Inspect XDR), Trend Vision One Endpoint Security, Trend Vision One XDR, Kaspersky Next (EDR Foundations · Optimum · Expert), Kaspersky Endpoint Security Cloud, Seqrite Endpoint Protection (on-prem), Seqrite Endpoint Protection Cloud, Seqrite EDR, Seqrite XDR (HawkkHunt), Xcitium ZeroDwell (containment), Xcitium EDR, Xcitium XDR, Xcitium OpenEDR, Check Point Harmony Endpoint, Cisco Secure Endpoint, Cisco XDR, Fortinet FortiEDR, Acronis Cyber Protect (EDR), Coro Endpoint & EDR, Hexnode XDR, Scalefusion Veltar and NinjaOne Endpoint Security (Bitdefender / SentinelOne). It flags Seqrite Endpoint Protection (on-prem) — Unverified above 2,000 endpoints, Seqrite Endpoint Protection Cloud — Unverified above 2,000 endpoints, Seqrite EDR — Unverified above 2,000 endpoints, Seqrite XDR (HawkkHunt) — Unverified above 2,000 endpoints, Xcitium ZeroDwell (containment) — Unverified above 2,000 endpoints, Xcitium EDR — Unverified above 2,000 endpoints, Xcitium XDR — Unverified above 2,000 endpoints, Xcitium OpenEDR — Unverified above 2,000 endpoints, Coro Endpoint & EDR — Unverified above 2,000 endpoints, Hexnode XDR — Unverified above 2,000 endpoints and Scalefusion Veltar — Unverified above 2,000 endpoints — marked on the cards, not removed.

India data residencyDocumented: SentinelOne (Mumbai), Sophos Central (Mumbai), Seqrite (India data centres and on-prem), Acronis (Mumbai), Scalefusion Veltar (India-hosted). CrowdStrike announced an India in-country cloud in January 2026 — announced, not yet documented live. NinjaOne's regions are US / EU / CA / OC (no India). Not documented either way for the rest — so no chip, and nothing is ruled out on it. Ask for the region in writing.

Platform bundling vs best-of-breedNot a chip because it is a strategy, not a capability: Defender inside Microsoft 365, NinjaOne / Hexnode / Scalefusion beside a UEM or RMM, Acronis beside backup, Sophos / Trend / Kaspersky / Bitdefender / ESET as platform suites, CrowdStrike / SentinelOne as the best-of-breed agents most other consoles integrate. The instrument tells you what each SKU does; whether one console or two is the right trade is the operating-capacity question.

Agent coexistenceRules nothing out but decides the rollout: Windows drops Defender Antivirus to passive mode when another engine registers, so any EPP here coexists with Defender for Endpoint telemetry; Xcitium EDR documents running beside Defender; two third-party real-time engines do not coexist — and the RMM's or UEM's bundled security is the usual way a second one arrives.

Under 50 endpointsRules nothing out on published minimums — Xcitium OpenEDR is free to 50, ESET sells 5-device packs, Defender for Business is sized to 300 users, Bitdefender and CrowdStrike Falcon Go sell small packs, Norton covers up to 20. Which enterprise tiers are a poor fit at this size is delivery-team judgement: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the operating question answered

Each shortlist states who will run it. If the answer is nobody, the shortlist changes — that is the point.

50–500 seats, no security team — someone else must watch it

Why: Managed detection priced for mid-market, sold with the agent by the same vendor: Sophos leads with MDR as the default product, Bitdefender and ESET sell it on top of published tiers.

The trade-off: MDR scope is endpoint-first and the contract is what you are buying — read the scope on the Managed Detection & Response guide before the licence.

Microsoft 365 E5 (or E5 Security) already in place

Why: Defender for Endpoint P2 is already paid for; a second EDR duplicates it. On E3 you hold only P1 — prevention — so the choice becomes E5 Security against a third-party EDR.

The trade-off: No file rollback in the agent, Defender Experts is a quote, and the console assumes Intune and Entra. One survivor here is the answer, not a gap.

Ransomware-scarred — file rollback is the requirement

Why: Documented automatic rollback: SentinelOne one-click on Windows, Sophos CryptoGuard from protected copies / VSS, Kaspersky's Remediation Engine; ESET and Bitdefender and Check Point qualify too.

The trade-off: Rollback has conditions (disk space, Windows-first) and restores files, not the breach. Xcitium's containment is the other bet; Acronis and Seqrite restore from their own backups.

A security team exists and wants to hunt

Why: Full EDR telemetry, advanced hunting, forensic timeline and scripted response — the reference agents, and the Microsoft-estate equivalent in P2.

The trade-off: Self-run EDR is a staffing decision: budget analysts or an MDR contract beside the licence. CrowdStrike has no rollback; SentinelOne has no published list.

India-regulated — on-prem console or India data centre

Why: On-prem consoles (Seqrite, ESET PROTECT On-Prem, GravityZone, Kaspersky Security Center, Check Point, FortiEDR) and India data centres (Seqrite, Acronis Mumbai, SentinelOne and Sophos Mumbai for cloud).

The trade-off: On-prem means you run the console server. If cloud with an India region is acceptable, SentinelOne and Sophos reopen the field; CrowdStrike's India cloud is announced, not yet live.

Budget decides — published prices, no sales cycle

Why: ESET from $42.20 and Bitdefender from $57 per device per year, Trend Vision One Endpoint Essentials from $2.25 per endpoint per month, Xcitium modular from $2.39 — on the vendors' own pages.

The trade-off: Published entry tiers are prevention-only; EDR costs more at every vendor. Bitdefender's first-year price renews higher — price year two.

You already run a UEM, an RMM or a backup agent — and want one console

Why: NinjaOne deploys and watches a resold Bitdefender / SentinelOne engine from the RMM; Acronis puts backup and EDR in one agent; Hexnode XDR and Scalefusion Veltar add security inside the UEM.

The trade-off: Depth follows the engine: NinjaOne's is real EDR, Acronis recovers by restore, Hexnode XDR is young and Veltar is hardening and access, not an EDR. One console is a convenience; the catch on the card is what you give up.

Prevention first, with containment instead of detection

Why: Xcitium contains unknown files at the kernel so nothing unrecognised runs; Sophos Intercept X Advanced is prevention with rollback; PHASR hardens the attack surface per user before prevention has to fire.

The trade-off: Containment can hold a benign-but-new binary until verdicted; PHASR is an add-on, not a protection engine; none of these is a substitute for someone watching when prevention misses.

The spine of the decision

“Rollback” is four mechanisms and one absence

Every datasheet says “ransomware protection”. What happens to the encrypted files is where the products genuinely differ — and the mechanism decides what you can promise the board.

Mechanism 1

Protected copy, then restore

Sophos CryptoGuard keeps a temporary copy when a business file is opened for write and restores it if the original is maliciously encrypted (needs ~3 GB free; no rollback if the process is stopped only after encryption completes). ESET's Ransomware Remediation keeps a protected backup store the attacker cannot modify; Check Point Anti-Ransomware restores from its own snapshots.

Mechanism 2

Agent-level rollback

SentinelOne restores encrypted files from its own snapshots on Windows in one action; Bitdefender's Ransomware Mitigation backs up and restores files touched by a detected attack; Kaspersky's Remediation Engine rolls back the malicious actions it recorded.

Mechanism 3

Contain before it runs — or restore from backup

Xcitium's ZeroDwell virtualises unknown files at the kernel so nothing unrecognised touches production — nothing to roll back because nothing executed. Acronis and Seqrite recover by restoring from their own backups: strong, but a restore, not a rollback.

The absence

Isolate, kill, restore from your backups

CrowdStrike, Defender for Endpoint, Cisco and Coro stop the process and isolate the host; files come back from your backup or OneDrive Files Restore, not from the agent. Strong response, no rollback — know which you bought. Trend, FortiEDR, Hexnode and NinjaOne's resold engine are not documented either way here.

Agent coexistence

One real-time engine per machine. Everything else can share.

  • Windows does the handshake for you: when a third-party engine registers with Windows Security Center, Microsoft Defender Antivirus drops to passive mode automatically — Defender for Endpoint keeps collecting EDR telemetry and can still block in EDR block mode. Automated investigation needs Defender AV present (passive or active), not removed.
  • Two third-party real-time engines do not coexist. The RMM’s “endpoint security” SKU (NinjaOne, TeamViewer, Splashtop), the UEM’s bundled AV (Hexnode XDR, Veltar) and the backup vendor’s (Acronis) are the usual way a second one arrives. Uninstall needs the tamper-protection password — plan it.
  • UEM and RMM agents are fine beside any of these with exclusions both ways: the EDR trusts the RMM’s installers and scripts; the RMM deploys and watches the EDR agent and never updates it.

Who runs it — the four operating models

The licence is the smaller half of every EDR.

  • Prevention only, run by IT. Entry tiers; the console is opened weekly for policy. Honest for many estates under ~300 seats — accept that nothing is hunting.
  • EDR run by your own analysts. Budget people, not just licences. CrowdStrike Insight, SentinelOne Complete, Defender P2, ESET Inspect, Trend Vision One and Kaspersky Expert are built for this model.
  • MDR from the vendor. Sophos MDR, SentinelOne Vigilance, Bitdefender MDR, ESET MDR, Kaspersky MDR, Trend Service One, Xcitium MDR, Seqrite MDR, Coro managed, Acronis MDR, FortiGuard; CrowdStrike Falcon Complete, Defender Experts, Check Point and Cisco at enterprise terms. The MDR guide compares scope and authority.
  • MDR from a partner / MSSP on whichever agent you chose — often the India-time-zone answer (Mitigata runs a 24×7 SOC from India). Which partners TechBag has delivered with: [TechBag to confirm].
What breaks as you grow

What changes at 200, 2,000 and 10,000 endpoints

Detection quality barely moves with size. Alert volume per analyst, exclusion sprawl and the managed contract’s scope are what move — and they decide whether the EDR tier is real or nominal.

200endpoints

The operating model is the constraint

  • Prevention-only is often the honest tier here; an EDR console with no owner becomes noise by week three.
  • Defender for Business, Falcon Go, ESET Entry, GravityZone Business, Trend Essentials, Xcitium's free tier and Norton are all sized for this band.
  • If you buy EDR, buy the managed tier with it — the licence is the smaller half.

Put this in your PoC

Run a detection-only week: count alerts, count the ones a human read, count the ones acted on.

2,000endpoints

Alert volume and exclusions are the constraint

  • Untuned EDR produces more alerts than a small team can triage; tuning and exclusions become an engineering task with an owner.
  • Agent coexistence with the UEM and RMM fleets must be documented per OS — one bad exclusion at this size is an outage.
  • MDR scope matters now: which alerts they take, which they hand back, what ‘response’ means in the SLA.

Put this in your PoC

Deploy to a 200-device ring with the RMM and UEM agents present; measure false positives and CPU for a week; read the MDR SLA aloud.

10,000endpoints

Telemetry, retention and the API are the constraint

  • Retention windows (days of searchable telemetry) and hunting query performance become line items.
  • Delegated, scoped administration by region or business unit is mandatory; console and API rate limits decide what you can automate.
  • Agent updates need rings of their own — a bad sensor release across 10,000 machines is the category's worst day, and it has happened.

Put this in your PoC

Pull 30 days of telemetry through the API; run your three hardest hunts; confirm staged sensor-update control in writing.

CrowdStrike, SentinelOne, Defender, Sophos, Bitdefender, ESET, Trend, Kaspersky, Check Point, Cisco, Fortinet, Acronis and NinjaOne's engines document estates far above 2,000 endpoints; Xcitium, Seqrite, Coro, Hexnode, Scalefusion Veltar and OpenEDR are flagged unverified at that size, not ruled out; Norton is licensed to 20. Where a specific console strains for your estate: [TechBag to confirm].

The switching cost

Swapping an EPP is a security event, not an install

The agent swap is scriptable through your UEM or RMM. What makes it expensive is the gap: the minutes between old engine off and new engine on, on every machine, and the tamper-protection password nobody remembers.

The agent

Push the new agent first (passive where the vendor supports it), then remove the old with its tamper-protection credential, then activate. Never the other order.

Exit costScriptable, in rings

Policies and exclusions

Exclusions for your line-of-business apps, the RMM, the UEM and backup agents are rebuilt by hand. Miss one and the first week is an outage.

Exit costRebuild

Detection history

Alerts, timelines and hunting data stay in the old console. Export what an audit might ask for before the licence ends.

Exit costExport or lose

The managed contract

MDR terms run on their own calendar. Overlap two services or end one early — either is a cost line nobody put in the licence comparison.

Exit costOverlap or gap

Cut-over plan and hours for your estate: [TechBag to confirm] — TechBag scopes it from your OS mix, the agents already present and the managed contract dates.

What it costs

The licence is the smaller half

What you may already hold, what the tiers cost in USD and INR, and the part that never appears on the licence line — the people who run it.

01

Do you already own one?

Four licences you may hold carry endpoint protection. One of them is usually the answer for a Microsoft estate.

Microsoft 365
Yes, if E5 or E5 Security (Defender for Endpoint P2 — full EDR) or Business Premium (Defender for Business). E3 carries P1 only: prevention, no EDR.
Your RMM / UEM
Sometimes NinjaOne resells Bitdefender / SentinelOne; Hexnode XDR and Scalefusion Veltar live inside the UEM; Acronis pairs EDR with backup. Check which engine — and that it is not a second one.
Your suite vendor
Often Sophos, Trend, Kaspersky, Bitdefender, ESET, Check Point, Cisco and Fortinet all bundle endpoint into their platform contracts. Read the SKU: prevention tier or EDR tier.
Google Workspace
No Gmail filters mail; Chrome Enterprise manages the browser. Neither is an endpoint protection agent for Windows, macOS or Linux.

If Defender P2 is already on your invoice, we say so first — and then talk about who will run it.

02

What the tiers cost

Published USD with INR for scale; per device per year unless the vendor prices per user per month; the EDR tier named separately from the prevention tier wherever the vendor publishes both. Seqrite’s and Acronis’s INR are the India list.

ESET PROTECT
Entry$42.20 ₹3,503Advanced$55 ₹4,565Complete$57.54 ₹4,776Elite (XDR)Quote

Term: per device / year; 5-device packs; Elite min 25; MDR on quote.

Bitdefender GravityZone
Small Business$57 ₹4,731Business Security$74 ₹6,142Premium (EDR)$95.89 ₹7,959XDR / MDRQuote

Term: per device / year, first-year promotional; renewals reported 2–3× higher.

CrowdStrike Falcon
Go (prevention)$59.99 ₹4,979Pro$99.99 ₹8,299Enterprise (EDR)$184.99 ₹15,354Complete (MDR)Quote

Term: per device / year; breakpoints at 500 / 1,000 / 5,000.

SentinelOne Singularity
Core~$69.99 ₹5,809Control~$79.99 ₹6,639Complete (EDR)~$179.99 ₹14,939Vigilance MDRAdd-on

Term: per endpoint / year reseller list — no vendor list; street $48–96 for Complete.

Microsoft Defender for Endpoint
P1$3 ₹249P2 (EDR)$5.20 ₹432E5 Security add-on$12 ₹996Bundled$0

Term: per user / month standalone; $0 marginal inside E3 (P1) / E5 (P2) / Business Premium (DfB).

Trend Vision One Endpoint
Essentials$2.25 ₹187Standard$5 ₹415Advanced (EDR)$14.92 ₹1,238XDRCredits

Term: per endpoint / month; Vision One credits for XDR and add-ons.

Kaspersky Next
Foundations (5 users)€287.50 ≈ ₹26,000OptimumQuote ExpertQuote MXDRQuote

Term: per 5 users / year entry; on-prem or cloud console.

Check Point Harmony Endpoint
Basic → Complete~$25–45 ₹2,075–₹3,735

Term: per user / year reported — no published list.

Cisco Secure Endpoint
Essentials$6.75 ₹560AdvantageQuote PremierQuote Cisco XDR~$69 / user / yr ₹5,727

Term: per user / month; XDR and hunting tiers quote-only.

Fortinet FortiEDR
Discover & Protect →~$20–35 ₹1,660–₹2,905

Term: per endpoint / year reported; list on quote.

Xcitium
Module (containment)$2.39 ₹198Endpoint security bundle$8.49 ₹705OpenEDR ≤50Free MDRQuote

Term: per endpoint / month, modular, postpaid.

Sophos Intercept X
Advanced~$30–50 reported ₹2,490–₹4,150with XDR~$48 reported ₹3,984MDR~$80–200+ reported ₹6,640–₹16,600

Term: per user / year; Sophos publishes no list — estimates only.

Seqrite Endpoint Protection
EPS Core₹799 ≈ $9.6+ EDR+₹350 (reported) ≈ $4.2XDR / MDRQuote

Term: per endpoint / year, INR-native through partners, GST invoiced.

Acronis Cyber Protect
Advanced + EDR~₹3,500 ≈ $42XDRQuote

Term: per workload / month, India reseller list; cloud or on-prem.

UEM / RMM-adjacent
Hexnode XDR$5.50 ₹457Scalefusion Veltar~$3–4 ₹249–₹332NinjaOne ES~$3–5 ₹249–₹415Norton SB (10 devices / yr)$179.99 ₹14,939

Term: per device / month (Norton per year); engines and depth differ — read the cards.

Coro
Endpoint / EDR module~$10.50 (historical) ₹872ManagedQuote

Term: per user / month; public list removed at the 2026 rebrand.

Tier-match before you compare. A prevention SKU against an EDR SKU is not a comparison: ESET Entry against Falcon Go, yes; ESET Entry against Falcon Enterprise, no. Every vendor here has both; price the job you will operate.
Term-match too. Bitdefender and Trend publish first-year and per-month figures; SentinelOne and Check Point are reseller-quoted annual; Seqrite and Acronis are INR annual lists. Year-two numbers are the honest ones.
Microsoft 365 E5 — what it does and doesn’t cover. E5 carries Defender for Endpoint P2 (full EDR), Defender for Office 365 P2, Identity and Cloud Apps — but Defender Experts (managed) is a separate quote, Linux and macOS depth trails the pure-plays, and there is no file rollback in the agent.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The analyst, or the MDR contract

An EDR tier without a person is a licence for a dashboard. Price the analyst headcount or the managed service beside the tier — Sophos MDR is reported at $80 ≈ ₹6,640$200 ≈ ₹16,600 per user per year on top of the agent; CrowdStrike Falcon Complete $25 ≈ ₹2,075$45 ≈ ₹3,735 per endpoint per month reported. That line is usually larger than the licence.

The renewal, not the promotion

First-year prices (Bitdefender’s in particular) renew at standard rates; reseller street prices (SentinelOne) move with volume; Microsoft’s E5 moved to $60 in July 2026. Ask for the year-two number in writing before comparing year one.

Removing the engine you replace

Tamper-protection credentials, a staged cut-over, exclusion rebuilds and a week of tuning — people-hours, not licence dollars. It sits in the switching-cost section, and the hours for your estate are [TechBag to confirm].

Before you commit

What goes wrong

Each of these is documented vendor behaviour; the matching to real TechBag engagements happens before any becomes a named case. They are cheaper to read now than to live through after the contract.

EDR bought, nobody triages it

The console fills; nobody owns it; by month three it is closed. The licence was the cheap half of a purchase that needed a person or a managed contract.

Two real-time engines on one machine

The RMM's security add-on, the UEM's XDR or the backup vendor's AV lands beside the EPP you chose. Both degrade; one blocks the other's updates. Only Defender is designed to step aside.

Assuming EPP covers response

Prevention tiers stop what they recognise and report the rest. When something gets through there is no timeline, no isolation, no hunt — because that was the next tier.

Rollback that doesn't cover what you assumed

Windows-first; needs free disk (Sophos ~3 GB); no rollback if the process was stopped after encryption finished; restores files, not the breach — and absent at CrowdStrike, Defender, Cisco and Coro.

Alert volume makes the console unusable

Untuned EDR at 2,000 endpoints outruns a small team within weeks; tuning and exclusions need an owner. The most common reason an EDR quietly fails.

E3 'includes Defender' — Plan 1, not Plan 2

Prevention only. The EDR is P2, in E5 or E5 Security. A buyer who stops at 'included' has no detection and believes they do.

Tamper protection blocks the migration

The old agent will not uninstall without its credential; the project stalls at machine one. Recover the password before you sign the new contract.

Year-two price shock

Promotional first-year pricing (Bitdefender), reseller street pricing (SentinelOne), credit consumption (Trend) and the July 2026 E5 rise all move at renewal. Compare year-two numbers, tier-matched, or the comparison is fiction.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Security map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.