{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"edr","name":"Endpoint detection & response","short":"EDR"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"edr-platforms","name":"EDR platforms","scope":"Comparable paid EDR-capable endpoint detection and response software; exclude staffed MDR services."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"How completely public documentation describes a production-operable EDR lifecycle from sensor through investigation and authorized response, including edition and operating-system constraints. Anchors are documented-evidence stages, not observed quality. Missing, gated, or unfetched procedure is unknown (null), never zero.","question":"How far does public documentation describe a production-operable EDR operating model for the evaluated paid edition?","anchors":["Public documentation states that the evaluated edition does not provide a sensor-through-response EDR operating model (EDR lifecycle explicitly absent or unsupported).","Marketing or overview pages describe endpoint protection or EDR at a high level without operating procedures or edition limits.","Product documentation describes sensor deployment and detection or alert generation for at least one operating system.","Documentation describes investigation of endpoint telemetry plus at least one authorized containment action, with stated edition prerequisites.","Documentation describes a repeatable operating model: role-gated response, session or command logging, and an OS-specific action matrix or equivalent policy split for the evaluated edition.","Documentation additionally describes production operating safeguards at scale (device-group or policy rings, automated or policy-driven response with human review or undo, and documented restore of containment) across the evaluated edition's supported platforms."],"refinements":[{"base":3,"criteria":[{"id":"response-permissions","label":"Role-gated response for the evaluated edition","weight":3},{"id":"response-audit","label":"Session or command audit logging","weight":4},{"id":"platform-actions","label":"OS-specific action matrix or equivalent response-policy split","weight":3}]},{"base":4,"criteria":[{"id":"deployment-groups","label":"Device groups or response-policy rings across the evaluated platform scope","weight":3},{"id":"supervised-automation","label":"Automated or policy-driven response with documented human review or undo","weight":4},{"id":"containment-restore","label":"Documented restoration from containment with platform boundaries","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented shipped operator workflows versus the ordinary current EDR baseline (remote shell, containment, and batch Real Time Response or equivalent host response). Stage 4 requires a distinct shipped workflow beyond that baseline, with constraints. Preview/Pre-GA and other-edition features do not count. AI branding and unique-market-first claims are out of scope. Anchors are documented-evidence stages, not observed quality; gaps are unknown (null), never zero.","question":"Which shipped operator workflows are documented beyond ordinary remote shell, containment, and batch host response?","anchors":["Public documentation states that the evaluated edition does not include detection or response workflows (for example a prevention-only SKU with EDR explicitly absent).","Documentation describes sensor plus alert generation only, with investigation and host response explicitly out of the edition.","Documentation describes investigation of endpoint telemetry (timeline, process tree, or equivalent) in addition to alerts, without a documented remote shell, containment, or batch host-response workflow in this edition.","Ordinary current EDR baseline: documentation describes remote shell, containment, and/or batch Real Time Response or equivalent host response for the evaluated edition, with stated OS or licensing limits.","One documented shipped workflow beyond that baseline (not ordinary remote shell, containment, or batch RTR), with edition or OS constraints stated. Preview/Pre-GA and extra-SKU features are excluded.","Two or more distinct shipped-beyond-baseline operator workflows documented with OS and edition limits; not merely branded features."]},{"id":"breadth","name":"Capability breadth","description":"Documented coverage of operating systems, investigation surfaces, and response actions for the evaluated paid edition, including stated gaps. Anchors are documented-evidence stages, not observed quality. Missing matrices are unknown (null), never zero.","question":"How broadly does public documentation enumerate OS coverage and per-platform investigation and response capabilities for this edition?","anchors":["Public documentation states that the evaluated edition supports no endpoint operating systems or lists zero investigation or response capabilities.","Single OS family with detect-only coverage.","Sensor on two OS families, or detect-plus-investigate on one OS family.","Documented Windows plus at least one additional OS family with EDR investigation; response may be Windows-skewed.","Documented Windows, macOS, and Linux sensors with investigation, plus at least isolate or equivalent containment on more than one OS family, with an explicit OS-capability matrix or equivalent command table.","Documented workstation and server coverage with response actions enumerated per OS including stated gaps, plus an additional documented workload class (mobile, identity, or cloud workload) that is in the evaluated edition rather than a separate SKU."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented integrations, APIs, and licensing boundaries with adjacent security platforms, excluding staffed MDR services. Anchors are documented-evidence stages, not observed quality. Unfetched APIs are unknown (null), never zero.","question":"How completely does public documentation describe APIs, native platform integrations, and licensing boundaries around this EDR edition?","anchors":["Public documentation states that the evaluated edition has no integrations, APIs, or export paths.","Native console only; documentation states no export or API.","Documented export, streaming, or management API.","Documented bidirectional or automation-capable API plus at least one named identity, device-management, SIEM, or SOAR integration path.","Documented connector catalog or native platform modules (identity, email, cloud, SOAR) with explicit licensing or module boundaries.","Documented extensible automation (custom APIs, SOAR playbooks, third-party response) with an auth model and stated which modules are extra SKUs."]},{"id":"governance","name":"Governance & control","description":"Documented operational safeguards for who may view telemetry versus take disruptive response, and how those actions are audited. Not observed security performance. Anchors are documented-evidence stages; missing RBAC or audit procedure is unknown (null), never zero.","question":"What documented access control, action gating, and audit of analyst response does this edition provide?","anchors":["Public documentation states that the evaluated edition provides no access control for viewing telemetry or taking response actions.","Documentation describes a shared console login or single admin role only.","Documentation mentions role-based access to the EDR console.","Documentation describes RBAC that separates viewing telemetry from taking response actions, and mentions audit of analyst actions.","Documentation describes live-response or equivalent permission tiers, session or command logs, and a path to restrict or undo disruptive actions.","Documentation describes tenant or device-group scoping, restriction of high-impact actions on critical assets, dedicated audit of response sessions, and restore of containment — all for the evaluated edition."]},{"id":"operations","name":"Operator enablement","description":"Documented analyst and administrator tooling to deploy, hunt, respond, and restore, including OS-specific operator limitations. Anchors are documented-evidence stages, not observed quality. Gated console runbooks are unknown (null), never zero.","question":"How completely does public documentation enable operators to deploy, hunt, respond, and restore on supported platforms?","anchors":["Public documentation states that operators cannot deploy, hunt, or respond with this edition (those operator functions are explicitly unsupported).","Marketing how-it-works only.","Deployment or onboarding documentation for the sensor.","Analyst investigation runbooks covering timeline or hunt plus at least one response action.","Documented hunting queries or command reference, live-response or remote-ops command matrix, and OS-specific operator limitations.","Documented health monitoring, containment restore procedures, and operator training or lab path in addition to stage 4."]}],"assessments":[{"vendor":"defender-for-endpoint","cohort":"edr-platforms","edition":"Microsoft Defender for Endpoint Plan 2 (not Plan 1; server coverage via Defender for Servers / Defender for Endpoint for servers)","asOf":"2026-09-21","status":"research-preview","summary":"Plan 2 provides endpoint investigation, hunting and live response with documented OS-specific limits. Server coverage requires an appropriate server entitlement. Standalone and manually triggered AIR ended on 1 September 2026; the documented replacement workflow is reflected in the scope.","dimensions":{"maturity":{"score":4.6,"confidence":"medium","rationale":"The established stage-4 EDR response model is supplemented by documented device grouping (+0.3) and release from isolation with OS boundaries (+0.3), yielding 4.6. The remaining supervised-automation credit is withheld: standalone AIR transition and XDR/preview features prevent a clean current Plan 2-only claim.","sourceIds":["s1","s3","s4","s6","s7","s10"],"refinement":{"base":4,"evidence":[{"criterion":"deployment-groups","rationale":"Plan 2 device-group procedures match devices by name, domain, tags and OS, rank overlapping groups and assign access. The credit is for controlled device grouping; deprecated standalone AIR is not counted as current automation.","sourceIds":["s10"]},{"criterion":"containment-restore","rationale":"Manual isolation documents Windows, macOS and Linux limits and a Release from isolation procedure; forced release has separate Windows prerequisites. This establishes restoration with explicit platform boundaries, not universal support for every response action.","sourceIds":["s6"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Plan 2 documents ordinary current EDR baseline: live-response remote shell, device isolation, and related host response, with OS and Plan 2 limits. That is stage 3, not stage 4. Investigation-package collection is ordinary IR. Automatic attack disruption, contain-user, and predictive shielding are Defender XDR and/or preview and are excluded. Legacy standalone AIR is not scored as current (ends as a separate/manual experience on 1 September 2026).","sourceIds":["s3","s5","s6"]},"breadth":{"score":4,"confidence":"medium","rationale":"Public procedures document Windows, macOS and Linux sensors, investigation, OS-specific commands and isolation with version and proxy caveats. Server coverage requires an appropriate server entitlement. Validate the current OS/action matrix for the proposed deployment.","sourceIds":["s1","s3","s6"]},"ecosystem":{"score":5,"confidence":"medium","rationale":"Management APIs support custom response automation and third-party deployment or SIEM connections. The delegated-access procedure documents Entra application registration, OAuth permissions and consent. Together with the named native integrations and explicit server/adjacent-product licensing boundaries, this meets anchor 5 for extensibility; it does not make Defender XDR workloads part of Plan 2.","sourceIds":["s1","s2","baseline-api","baseline-auth"]},"governance":{"score":4,"confidence":"medium","rationale":"Role-gated live response records commands and supports restricting or undoing response; device groups scope access. The separate high-value-asset restriction procedure depends on preview deployment tooling and platform prerequisites. It is not used to establish the complete anchor-5 safeguard set.","sourceIds":["s3","s6","s7","s10","baseline-critical"]},"operations":{"score":5,"confidence":"medium","rationale":"The Plan 2 sensor-health report supplies device health and reporting procedures; the pilot guide adds onboarding verification, evaluation labs and investigation exercises. Existing live-response command tables and release-from-isolation procedures establish the remaining anchor-5 conditions. Deprecated standalone AIR exercises do not support this score.","sourceIds":["s3","s6","s9","baseline-health","baseline-pilot"]}},"constraints":["Evaluated edition is Plan 2. Plan 1 documents only run AV scan, isolate device, stop and quarantine a file, and file indicators — not EDR timeline, live response, or advanced hunting.","Microsoft 365 E5 / E5 Security include Plan 2; servers are licensed separately (Defender for Endpoint for servers / Defender for Servers) with possible dual-license discounts.","Live response requires Plan 2, Advanced features enablement, and OS/sensor version floors (for example macOS 101.43.84+, Linux 101.45.13+; down-level Windows Server needs Unified Agent).","Live response commands are not equivalent across OS: many Windows-only commands (registry, services, scheduled tasks, isolate-from-live-response on macOS only in the advanced table).","As of 1 September 2026, AIR is documented as no longer a separate/manual investigation experience; detection/response moves into the default antivirus stack, with on-demand full AV scan. Do not treat legacy standalone AIR as current.","Advanced hunting queries native Defender data for 30 days; portal visibility is 180 days. Longer hunt retention needs Sentinel analytics-tier retention or streaming APIs.","Automatic attack disruption, contain-user, GPO/Safeboot hardening, and some IP-containment behaviors are Defender XDR / preview-scoped and may require additional workloads (for example Defender for Identity).","Public-docs-only research; no lab validation of detection quality or isolation side effects.","The high-value-asset restriction guide depends on the Defender deployment tool marked preview; that procedure earns no GA governance credit in this baseline."],"sources":[{"id":"s1","title":"Microsoft Defender for Endpoint overview","url":"https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Overview of Microsoft Defender for Endpoint Plan 1","url":"https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-plan-1","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Investigate entities on devices using live response","url":"https://learn.microsoft.com/en-us/defender-endpoint/live-response","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Use automated investigations to investigate and remediate threats","url":"https://learn.microsoft.com/en-us/defender-endpoint/automated-investigations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Overview of endpoint detection and response capabilities","url":"https://learn.microsoft.com/en-us/defender-endpoint/overview-endpoint-detection-response","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Take response actions on a device","url":"https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Use role-based access control in the Microsoft Defender portal","url":"https://learn.microsoft.com/en-us/defender-endpoint/rbac","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Microsoft Defender for Endpoint data storage and privacy","url":"https://learn.microsoft.com/en-us/defender-endpoint/data-storage-privacy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Advanced hunting overview in Microsoft Defender XDR","url":"https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Create and manage device groups in Microsoft Defender for Endpoint","url":"https://learn.microsoft.com/en-us/defender-endpoint/machine-groups","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-health","title":"Device health: sensor health and OS","url":"https://learn.microsoft.com/en-us/defender-endpoint/device-health-sensor-health-os","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-pilot","title":"Pilot and deploy Microsoft Defender for Endpoint","url":"https://learn.microsoft.com/en-us/defender-xdr/pilot-deploy-defender-endpoint","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-api","title":"Supported Microsoft Defender for Endpoint APIs","url":"https://learn.microsoft.com/en-us/defender-endpoint/api/management-apis","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-auth","title":"Use Microsoft Defender for Endpoint APIs with delegated permissions","url":"https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-nativeapp","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-critical","title":"Restrict response actions on high-value assets","url":"https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Microsoft Defender for Endpoint Plan 2","company":"Microsoft","profileUrl":"/landscape/vendors/defender-for-endpoint/"},{"vendor":"crowdstrike-falcon-insight","cohort":"edr-platforms","edition":"CrowdStrike Falcon Insight XDR (EDR entitlement on the Falcon sensor; not Falcon Complete MDR)","asOf":"2026-09-21","status":"research-preview","summary":"Insight XDR is CrowdStrike's paid EDR/XDR software entitlement: sensor telemetry, detections, host containment, and Real Time Response with role-tiered commands. Falcon Complete MDR, OverWatch hunting, and native identity/cloud/mobile context are documented as separate modules or services. Console how-to pages are login-gated; public evidence is strongest in developer APIs and the deployment FAQ.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Sensor, telemetry investigation and containment already establish stage 3. Current public response-policy and dedicated RTR Audit documentation establish all three stage-4 requirements: role gating, session/command audit records and an OS-specific policy split. The score advances to 4.0. This does not establish observed operational quality or all stage-5 safeguards.","sourceIds":["s2","s3","s5","s6","s7"],"refinement":{"base":3,"evidence":[{"criterion":"response-permissions","rationale":"Response-policy documentation restricts custom scripts to RTR Active Responder or Administrator and Falcon scripts to Administrator. These are explicit response roles, not merely API authentication.","sourceIds":["s5"]},{"criterion":"response-audit","rationale":"The dedicated RTR Audit API retrieves session records and optionally command information, including logs, user identity and timing. This is audit evidence distinct from the ordinary command-status API.","sourceIds":["s7"]},{"criterion":"platform-actions","rationale":"The response-policy schema names Windows, Mac and Linux and distinguishes common commands from Windows-only options and Mac support for put-and-run.","sourceIds":["s5"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Insight XDR documents ordinary current EDR baseline: host containment, Real Time Response remote shell, and batch RTR. Under the calibrated rubric those are stage 3, not stage 4. Fusion SOAR and native identity/cloud/mobile response are module- or service-dependent and not used for a higher stage. Charlotte AI is ignored as branding.","sourceIds":["s1","s3","s4"]},"breadth":{"score":3,"confidence":"medium","rationale":"The deployment FAQ documents Windows, macOS and Linux sensors; RTR policies distinguish these operating systems and identify command restrictions. This supports multi-OS investigation. The captured sources do not establish the complete containment/action matrix needed for stage 4; validate the current supported OS and command matrix.","sourceIds":["s2","s5"]},"ecosystem":{"score":3,"confidence":"low","rationale":"Developer APIs cover hosts, RTR, and RTR admin with OAuth scopes. The product page names Falcon Fusion SOAR and optional identity/cloud/mobile/data-protection context plus third-party ingest. Stage 4 is not claimed: native XDR across those domains is documented as requiring additional supported Falcon modules after a platform upgrade, and the dedicated native-XDR article did not return full body on fetch.","sourceIds":["s1","s3","s6"]},"governance":{"score":4,"confidence":"medium","rationale":"Public RTR documentation distinguishes read-only, active-responder and administrator permission levels. Response policies restrict scripts and commands by operating system and assigned host groups; the dedicated RTR Audit API returns session records with optional command logs, user identity and timing. Together these establish the stage-4 permission, audit and action-restriction requirements. The Foundry page is used only for the RTR permission taxonomy, not to credit Foundry or Fusion entitlements. Complete critical-asset safeguards and the full stage-5 operating model are not established by this review.","sourceIds":["s4","s5","s7"]},"operations":{"score":4,"confidence":"medium","rationale":"Public RTR API commands and response-policy documentation provide a remote-operations reference with Windows, macOS and Linux policy differences, including platform-specific script and execution limits. This satisfies anchor 4 without requiring a console-only cheat sheet. A complete public health, restoration and lab path for anchor 5 remains unverified.","sourceIds":["s2","s3","s5"]}},"constraints":["Evaluated software entitlement is Falcon Insight XDR. Falcon Complete MDR, managed threat hunting, and OverWatch are staffed services and are out of cohort.","Native XDR context from identity, cloud, mobile, and data protection is documented as requiring additional supported Falcon modules, not as an automatic Insight-only feature.","Falcon for Legacy Systems, Falcon Insight for ChromeOS, and Falcon for Mobile are separate coverage paths; ChromeOS uses Google event ingest without a Falcon agent.","RTR must be enabled in a per-platform response policy. Several powerful commands (memory dump, Falcon scripts, put-and-run) are Windows-only or Windows/Mac-only in the Terraform schema.","Identity protection requires the sensor on 64-bit Windows domain controllers.","Customer console documentation for detections, Event Search, and RTR UI is not publicly fetchable; scores lean on developer APIs and marketing/FAQ pages.","Do not treat product-page ROI, SE Labs, or MTT* figures as ordinal evidence."],"sources":[{"id":"s1","title":"CrowdStrike Falcon Insight XDR product page","url":"https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-insight-xdr/","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"CrowdStrike Deployment FAQ (sensor OS support)","url":"https://www.crowdstrike.com/en-us/products/faq/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"CrowdStrike Real Time Response API collection","url":"https://developer.crowdstrike.com/api-reference/collections/real-time-response/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"CrowdStrike Foundry RTR Scripts (permission levels)","url":"https://developer.crowdstrike.com/foundry/logic-capabilities/rtr-scripts/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"CrowdStrike Terraform response_policy resource","url":"https://developer.crowdstrike.com/cac/terraform/provider/host-setup-and-management/resources/response-policy/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"CrowdStrike Hosts API collection","url":"https://developer.crowdstrike.com/api-reference/collections/hosts/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Real Time Response Audit API","url":"https://developer.crowdstrike.com/api-reference/collections/real-time-response-audit/","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Falcon Insight XDR","company":"CrowdStrike","profileUrl":"/landscape/vendors/crowdstrike-falcon-insight/"},{"vendor":"sentinelone-singularity-endpoint","cohort":"edr-platforms","edition":"SentinelOne Singularity Complete (endpoint package including Core and Control; not Wayfinder MDR)","asOf":"2026-09-21","status":"research-preview","summary":"Singularity Complete is the paid endpoint package that adds Deep Visibility/EDR, Storyline hunting, remote shell, and advertised 1-click rollback on top of Core NGAV and Control suite features. Rollback is documented as Windows VSS-based; Core vs Control vs Complete must be distinguished. Wayfinder/Singularity MDR is a staffed service and is out of scope.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Complete product pages document Storyline investigation, kill/quarantine/remediate/rollback, network disconnect, and Full Remote Shell, plus Core/Control/Complete packaging. Stage 4 is not claimed: public pages do not provide a role-gated response matrix, session/command logs, or an OS-specific action table comparable to MDE live response.","sourceIds":["s2","s3","s4"]},"innovation":{"score":null,"confidence":"low","rationale":"The sources describe Storyline, remote response and Windows-oriented rollback, but this pass does not establish a defensible difference from the current EDR baseline across the selected edition. A narrative or rollback marketing description alone is insufficient to assign a beyond-baseline stage.","sourceIds":["s2","s3","s6","s7"]},"breadth":{"score":3,"confidence":"low","rationale":"Core FAQ lists Windows (including some legacy), macOS, and multiple Linux distributions, plus VDI/cloud guests. Complete advertises network block and remote shell. Stage 4 is not claimed: the public macOS list on Core looks stale versus Day-0 marketing, and rollback is documented as Windows VSS-centric. Confidence is low because OS-capability matrices for response are marketing-level.","sourceIds":["s3","s4","s6"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Complete FAQ documents Cloud Funnel replication/export of EDR data to a customer SIEM, Amazon S3, or GCS. That is documented export (stage 2). Stage 3 is not claimed: no bidirectional or automation-capable API was fetched, and Marketplace/Identity/Wayfinder names are adjacent products, not API proof.","sourceIds":["s1","s2","s3"]},"governance":{"score":null,"confidence":"low","rationale":"Fetched Complete and Control pages describe policy-driven response and hierarchical Control policies but do not document RBAC, view-versus-response role split, or analyst-action audit. Stage 2 requires documented role-based access; that evidence is absent, so the score is unknown (null), not 2 and not 0.","sourceIds":["s3","s5"]},"operations":{"score":3,"confidence":"medium","rationale":"Storyline/Deep Visibility blog documents query construction, MITRE indicator search across Windows/Linux/macOS, and saved Watchlists. Complete describes mitigate actions and remote shell at a product level. Stage 4 is not claimed: there is no public remote-ops command reference or rollback restore runbook with OS limits.","sourceIds":["s3","s6","s7"]}},"constraints":["Evaluated package is Singularity Complete (includes Core and Control). Core is NGAV/EPP; Control adds firewall/device control and Rogues. Deep Visibility EDR, remote shell, and extended hunting are Complete-tier in the fetched packaging pages.","Wayfinder MDR / Singularity MDR is a staffed service and is excluded from this software assessment.","Standard historical EDR retention is documented as 14 days, with a paid option up to 365 days; malware/fileless incident retention is separately advertised at 365 days. Confirm the contracted retention, not the marketing maximum.","Rollback is documented on SentinelOne's own explainer as relying on Windows Volume Shadow Copy Service, with snapshots described as every 4 hours and VSS-tamper protection. Do not assume macOS/Linux rollback parity.","Core FAQ Windows Server list on the fetched page stops at 2019 and macOS examples include older releases; treat that list as incomplete pending current agent-release notes (login-gated).","Singularity Identity, Ranger (beyond Rogues), Purple AI, Cloud Funnel destinations, and Marketplace connectors may be extra modules.","No public console RBAC or RemoteOps command matrix was fetched; governance is unknown (null), not a low numeric score."],"sources":[{"id":"s1","title":"Singularity Endpoint Security Platform","url":"https://www.sentinelone.com/platform/endpoint-security/","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"Singularity Endpoint Protection Platform","url":"https://www.sentinelone.com/platform/endpoint-protection-platform/","accessedAt":"2026-09-21","kind":"product"},{"id":"s3","title":"Singularity Complete","url":"https://www.sentinelone.com/platform/singularity-complete/","accessedAt":"2026-09-21","kind":"product"},{"id":"s4","title":"Singularity Core","url":"https://www.sentinelone.com/platform/singularity-core/","accessedAt":"2026-09-21","kind":"product"},{"id":"s5","title":"Singularity Control","url":"https://www.sentinelone.com/platform/singularity-control/","accessedAt":"2026-09-21","kind":"product"},{"id":"s6","title":"What is Ransomware Rollback?","url":"https://www.sentinelone.com/cybersecurity-101/cybersecurity/what-is-ransomware-rollback/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Rapid Threat Hunting with Storylines — Feature Spotlight","url":"https://www.sentinelone.com/blog/rapid-threat-hunting-with-deep-visibility-feature-spotlight/","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Singularity Endpoint","company":"SentinelOne","profileUrl":"/landscape/vendors/sentinelone-singularity-endpoint/"}],"scenarios":[{"id":"lean-soc","name":"Small security team","description":"A lean SOC needs Plan/SKU-accurate EDR investigation and containment without assuming a staffed MDR service will operate the console.","priorities":["operations","governance","maturity"],"questions":["Which exact paid edition (MDE Plan 2 vs Plan 1; Falcon Insight vs Complete MDR; Singularity Complete vs Core) is on the quote?","Who is allowed to isolate a host or open a live/remote shell, and where are those actions logged?","What is the contracted telemetry retention for hunting versus alert/incident views?"]},{"id":"mixed-os-estate","name":"Mixed Windows, macOS, and Linux estate","description":"Operators must confirm that investigation and disruptive response exist on each planned OS release, not only on Windows workstations.","priorities":["breadth","operations","innovation"],"questions":["For each planned OS version, which response actions are documented: isolate, kill/quarantine, live/remote shell, rollback?","Do servers use a different SKU (Defender for Servers, extra Falcon module, Linux workload SKU)?","If ransomware rollback is a requirement, is it documented for non-Windows hosts in the selected package?"]}],"researchNotes":["Paid EDR software is compared using a current baseline of telemetry, detection, investigation, containment and remote response. Stages describe documented workflows, not efficacy, reliability or market leadership. Public-documentation confidence is at most medium.","Three pilots cover paid EDR-capable software editions; staffed MDR services are excluded. Public developer APIs and edition pages supplement procedural documentation, with evidence limitations recorded per cell.","Each assessment names one paid EDR edition. Adjacent modules and licensing requirements are recorded as constraints and do not silently expand its scope.","Evidence gap: Falcon console documentation and SentinelOne agent-release notes are login-gated. Public developer APIs and edition pages support only the stages recorded here; unsupported permission and operating details remain null.","Scope limitation: Microsoft Defender XDR automatic attack disruption and CrowdStrike native XDR extra-module entitlements sit beside endpoint EDR. They are treated as ecosystem/licensing boundaries, not as free EDR-baseline features.","Microsoft documents that, from 1 September 2026, AIR is no longer a separate or manually triggered investigation experience. Plan 2 live response retains operating-system-specific commands and prerequisites.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","The maturity review also identified a governance correction for Falcon Insight XDR: the public RTR Audit API and response-policy permission restrictions establish anchor 4.0. This is a documented-evidence correction, not a claim of recent product improvement.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."],"history":{"segment":"edr","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"edr","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"edr-platforms","name":"EDR platforms","scope":"Comparable paid EDR-capable endpoint detection and response software; exclude staffed MDR services."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"How completely public documentation describes a production-operable EDR lifecycle from sensor through investigation and authorized response, including edition and operating-system constraints. Anchors are documented-evidence stages, not observed quality. Missing, gated, or unfetched procedure is unknown (null), never zero.","question":"How far does public documentation describe a production-operable EDR operating model for the evaluated paid edition?","anchors":["Public documentation states that the evaluated edition does not provide a sensor-through-response EDR operating model (EDR lifecycle explicitly absent or unsupported).","Marketing or overview pages describe endpoint protection or EDR at a high level without operating procedures or edition limits.","Product documentation describes sensor deployment and detection or alert generation for at least one operating system.","Documentation describes investigation of endpoint telemetry plus at least one authorized containment action, with stated edition prerequisites.","Documentation describes a repeatable operating model: role-gated response, session or command logging, and an OS-specific action matrix or equivalent policy split for the evaluated edition.","Documentation additionally describes production operating safeguards at scale (device-group or policy rings, automated or policy-driven response with human review or undo, and documented restore of containment) across the evaluated edition's supported platforms."],"refinements":[{"base":3,"criteria":[{"id":"response-permissions","label":"Role-gated response for the evaluated edition","weight":3},{"id":"response-audit","label":"Session or command audit logging","weight":4},{"id":"platform-actions","label":"OS-specific action matrix or equivalent response-policy split","weight":3}]},{"base":4,"criteria":[{"id":"deployment-groups","label":"Device groups or response-policy rings across the evaluated platform scope","weight":3},{"id":"supervised-automation","label":"Automated or policy-driven response with documented human review or undo","weight":4},{"id":"containment-restore","label":"Documented restoration from containment with platform boundaries","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented shipped operator workflows versus the ordinary current EDR baseline (remote shell, containment, and batch Real Time Response or equivalent host response). Stage 4 requires a distinct shipped workflow beyond that baseline, with constraints. Preview/Pre-GA and other-edition features do not count. AI branding and unique-market-first claims are out of scope. Anchors are documented-evidence stages, not observed quality; gaps are unknown (null), never zero.","question":"Which shipped operator workflows are documented beyond ordinary remote shell, containment, and batch host response?","anchors":["Public documentation states that the evaluated edition does not include detection or response workflows (for example a prevention-only SKU with EDR explicitly absent).","Documentation describes sensor plus alert generation only, with investigation and host response explicitly out of the edition.","Documentation describes investigation of endpoint telemetry (timeline, process tree, or equivalent) in addition to alerts, without a documented remote shell, containment, or batch host-response workflow in this edition.","Ordinary current EDR baseline: documentation describes remote shell, containment, and/or batch Real Time Response or equivalent host response for the evaluated edition, with stated OS or licensing limits.","One documented shipped workflow beyond that baseline (not ordinary remote shell, containment, or batch RTR), with edition or OS constraints stated. Preview/Pre-GA and extra-SKU features are excluded.","Two or more distinct shipped-beyond-baseline operator workflows documented with OS and edition limits; not merely branded features."]},{"id":"breadth","name":"Capability breadth","description":"Documented coverage of operating systems, investigation surfaces, and response actions for the evaluated paid edition, including stated gaps. Anchors are documented-evidence stages, not observed quality. Missing matrices are unknown (null), never zero.","question":"How broadly does public documentation enumerate OS coverage and per-platform investigation and response capabilities for this edition?","anchors":["Public documentation states that the evaluated edition supports no endpoint operating systems or lists zero investigation or response capabilities.","Single OS family with detect-only coverage.","Sensor on two OS families, or detect-plus-investigate on one OS family.","Documented Windows plus at least one additional OS family with EDR investigation; response may be Windows-skewed.","Documented Windows, macOS, and Linux sensors with investigation, plus at least isolate or equivalent containment on more than one OS family, with an explicit OS-capability matrix or equivalent command table.","Documented workstation and server coverage with response actions enumerated per OS including stated gaps, plus an additional documented workload class (mobile, identity, or cloud workload) that is in the evaluated edition rather than a separate SKU."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented integrations, APIs, and licensing boundaries with adjacent security platforms, excluding staffed MDR services. Anchors are documented-evidence stages, not observed quality. Unfetched APIs are unknown (null), never zero.","question":"How completely does public documentation describe APIs, native platform integrations, and licensing boundaries around this EDR edition?","anchors":["Public documentation states that the evaluated edition has no integrations, APIs, or export paths.","Native console only; documentation states no export or API.","Documented export, streaming, or management API.","Documented bidirectional or automation-capable API plus at least one named identity, device-management, SIEM, or SOAR integration path.","Documented connector catalog or native platform modules (identity, email, cloud, SOAR) with explicit licensing or module boundaries.","Documented extensible automation (custom APIs, SOAR playbooks, third-party response) with an auth model and stated which modules are extra SKUs."]},{"id":"governance","name":"Governance & control","description":"Documented operational safeguards for who may view telemetry versus take disruptive response, and how those actions are audited. Not observed security performance. Anchors are documented-evidence stages; missing RBAC or audit procedure is unknown (null), never zero.","question":"What documented access control, action gating, and audit of analyst response does this edition provide?","anchors":["Public documentation states that the evaluated edition provides no access control for viewing telemetry or taking response actions.","Documentation describes a shared console login or single admin role only.","Documentation mentions role-based access to the EDR console.","Documentation describes RBAC that separates viewing telemetry from taking response actions, and mentions audit of analyst actions.","Documentation describes live-response or equivalent permission tiers, session or command logs, and a path to restrict or undo disruptive actions.","Documentation describes tenant or device-group scoping, restriction of high-impact actions on critical assets, dedicated audit of response sessions, and restore of containment — all for the evaluated edition."]},{"id":"operations","name":"Operator enablement","description":"Documented analyst and administrator tooling to deploy, hunt, respond, and restore, including OS-specific operator limitations. Anchors are documented-evidence stages, not observed quality. Gated console runbooks are unknown (null), never zero.","question":"How completely does public documentation enable operators to deploy, hunt, respond, and restore on supported platforms?","anchors":["Public documentation states that operators cannot deploy, hunt, or respond with this edition (those operator functions are explicitly unsupported).","Marketing how-it-works only.","Deployment or onboarding documentation for the sensor.","Analyst investigation runbooks covering timeline or hunt plus at least one response action.","Documented hunting queries or command reference, live-response or remote-ops command matrix, and OS-specific operator limitations.","Documented health monitoring, containment restore procedures, and operator training or lab path in addition to stage 4."]}],"assessments":[{"vendor":"defender-for-endpoint","cohort":"edr-platforms","edition":"Microsoft Defender for Endpoint Plan 2 (not Plan 1; server coverage via Defender for Servers / Defender for Endpoint for servers)","asOf":"2026-09-21","status":"research-preview","summary":"Plan 2 provides endpoint investigation, hunting and live response with documented OS-specific limits. Server coverage requires an appropriate server entitlement. Standalone and manually triggered AIR ended on 1 September 2026; the documented replacement workflow is reflected in the scope.","dimensions":{"maturity":{"score":4.6,"confidence":"medium","rationale":"The established stage-4 EDR response model is supplemented by documented device grouping (+0.3) and release from isolation with OS boundaries (+0.3), yielding 4.6. The remaining supervised-automation credit is withheld: standalone AIR transition and XDR/preview features prevent a clean current Plan 2-only claim.","sourceIds":["s1","s3","s4","s6","s7","s10"],"refinement":{"base":4,"evidence":[{"criterion":"deployment-groups","rationale":"Plan 2 device-group procedures match devices by name, domain, tags and OS, rank overlapping groups and assign access. The credit is for controlled device grouping; deprecated standalone AIR is not counted as current automation.","sourceIds":["s10"]},{"criterion":"containment-restore","rationale":"Manual isolation documents Windows, macOS and Linux limits and a Release from isolation procedure; forced release has separate Windows prerequisites. This establishes restoration with explicit platform boundaries, not universal support for every response action.","sourceIds":["s6"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Plan 2 documents ordinary current EDR baseline: live-response remote shell, device isolation, and related host response, with OS and Plan 2 limits. That is stage 3, not stage 4. Investigation-package collection is ordinary IR. Automatic attack disruption, contain-user, and predictive shielding are Defender XDR and/or preview and are excluded. Legacy standalone AIR is not scored as current (ends as a separate/manual experience on 1 September 2026).","sourceIds":["s3","s5","s6"]},"breadth":{"score":4,"confidence":"medium","rationale":"Public procedures document Windows, macOS and Linux sensors, investigation, OS-specific commands and isolation with version and proxy caveats. Server coverage requires an appropriate server entitlement. Validate the current OS/action matrix for the proposed deployment.","sourceIds":["s1","s3","s6"]},"ecosystem":{"score":5,"confidence":"medium","rationale":"Management APIs support custom response automation and third-party deployment or SIEM connections. The delegated-access procedure documents Entra application registration, OAuth permissions and consent. Together with the named native integrations and explicit server/adjacent-product licensing boundaries, this meets anchor 5 for extensibility; it does not make Defender XDR workloads part of Plan 2.","sourceIds":["s1","s2","baseline-api","baseline-auth"]},"governance":{"score":4,"confidence":"medium","rationale":"Role-gated live response records commands and supports restricting or undoing response; device groups scope access. The separate high-value-asset restriction procedure depends on preview deployment tooling and platform prerequisites. It is not used to establish the complete anchor-5 safeguard set.","sourceIds":["s3","s6","s7","s10","baseline-critical"]},"operations":{"score":5,"confidence":"medium","rationale":"The Plan 2 sensor-health report supplies device health and reporting procedures; the pilot guide adds onboarding verification, evaluation labs and investigation exercises. Existing live-response command tables and release-from-isolation procedures establish the remaining anchor-5 conditions. Deprecated standalone AIR exercises do not support this score.","sourceIds":["s3","s6","s9","baseline-health","baseline-pilot"]}},"constraints":["Evaluated edition is Plan 2. Plan 1 documents only run AV scan, isolate device, stop and quarantine a file, and file indicators — not EDR timeline, live response, or advanced hunting.","Microsoft 365 E5 / E5 Security include Plan 2; servers are licensed separately (Defender for Endpoint for servers / Defender for Servers) with possible dual-license discounts.","Live response requires Plan 2, Advanced features enablement, and OS/sensor version floors (for example macOS 101.43.84+, Linux 101.45.13+; down-level Windows Server needs Unified Agent).","Live response commands are not equivalent across OS: many Windows-only commands (registry, services, scheduled tasks, isolate-from-live-response on macOS only in the advanced table).","As of 1 September 2026, AIR is documented as no longer a separate/manual investigation experience; detection/response moves into the default antivirus stack, with on-demand full AV scan. Do not treat legacy standalone AIR as current.","Advanced hunting queries native Defender data for 30 days; portal visibility is 180 days. Longer hunt retention needs Sentinel analytics-tier retention or streaming APIs.","Automatic attack disruption, contain-user, GPO/Safeboot hardening, and some IP-containment behaviors are Defender XDR / preview-scoped and may require additional workloads (for example Defender for Identity).","Public-docs-only research; no lab validation of detection quality or isolation side effects.","The high-value-asset restriction guide depends on the Defender deployment tool marked preview; that procedure earns no GA governance credit in this baseline."],"sources":[{"id":"s1","title":"Microsoft Defender for Endpoint overview","url":"https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Overview of Microsoft Defender for Endpoint Plan 1","url":"https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-plan-1","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Investigate entities on devices using live response","url":"https://learn.microsoft.com/en-us/defender-endpoint/live-response","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Use automated investigations to investigate and remediate threats","url":"https://learn.microsoft.com/en-us/defender-endpoint/automated-investigations","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Overview of endpoint detection and response capabilities","url":"https://learn.microsoft.com/en-us/defender-endpoint/overview-endpoint-detection-response","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Take response actions on a device","url":"https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Use role-based access control in the Microsoft Defender portal","url":"https://learn.microsoft.com/en-us/defender-endpoint/rbac","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s8","title":"Microsoft Defender for Endpoint data storage and privacy","url":"https://learn.microsoft.com/en-us/defender-endpoint/data-storage-privacy","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s9","title":"Advanced hunting overview in Microsoft Defender XDR","url":"https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s10","title":"Create and manage device groups in Microsoft Defender for Endpoint","url":"https://learn.microsoft.com/en-us/defender-endpoint/machine-groups","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-health","title":"Device health: sensor health and OS","url":"https://learn.microsoft.com/en-us/defender-endpoint/device-health-sensor-health-os","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-pilot","title":"Pilot and deploy Microsoft Defender for Endpoint","url":"https://learn.microsoft.com/en-us/defender-xdr/pilot-deploy-defender-endpoint","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-api","title":"Supported Microsoft Defender for Endpoint APIs","url":"https://learn.microsoft.com/en-us/defender-endpoint/api/management-apis","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-auth","title":"Use Microsoft Defender for Endpoint APIs with delegated permissions","url":"https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-nativeapp","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-critical","title":"Restrict response actions on high-value assets","url":"https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"crowdstrike-falcon-insight","cohort":"edr-platforms","edition":"CrowdStrike Falcon Insight XDR (EDR entitlement on the Falcon sensor; not Falcon Complete MDR)","asOf":"2026-09-21","status":"research-preview","summary":"Insight XDR is CrowdStrike's paid EDR/XDR software entitlement: sensor telemetry, detections, host containment, and Real Time Response with role-tiered commands. Falcon Complete MDR, OverWatch hunting, and native identity/cloud/mobile context are documented as separate modules or services. Console how-to pages are login-gated; public evidence is strongest in developer APIs and the deployment FAQ.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Sensor, telemetry investigation and containment already establish stage 3. Current public response-policy and dedicated RTR Audit documentation establish all three stage-4 requirements: role gating, session/command audit records and an OS-specific policy split. The score advances to 4.0. This does not establish observed operational quality or all stage-5 safeguards.","sourceIds":["s2","s3","s5","s6","s7"],"refinement":{"base":3,"evidence":[{"criterion":"response-permissions","rationale":"Response-policy documentation restricts custom scripts to RTR Active Responder or Administrator and Falcon scripts to Administrator. These are explicit response roles, not merely API authentication.","sourceIds":["s5"]},{"criterion":"response-audit","rationale":"The dedicated RTR Audit API retrieves session records and optionally command information, including logs, user identity and timing. This is audit evidence distinct from the ordinary command-status API.","sourceIds":["s7"]},{"criterion":"platform-actions","rationale":"The response-policy schema names Windows, Mac and Linux and distinguishes common commands from Windows-only options and Mac support for put-and-run.","sourceIds":["s5"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Insight XDR documents ordinary current EDR baseline: host containment, Real Time Response remote shell, and batch RTR. Under the calibrated rubric those are stage 3, not stage 4. Fusion SOAR and native identity/cloud/mobile response are module- or service-dependent and not used for a higher stage. Charlotte AI is ignored as branding.","sourceIds":["s1","s3","s4"]},"breadth":{"score":3,"confidence":"medium","rationale":"The deployment FAQ documents Windows, macOS and Linux sensors; RTR policies distinguish these operating systems and identify command restrictions. This supports multi-OS investigation. The captured sources do not establish the complete containment/action matrix needed for stage 4; validate the current supported OS and command matrix.","sourceIds":["s2","s5"]},"ecosystem":{"score":3,"confidence":"low","rationale":"Developer APIs cover hosts, RTR, and RTR admin with OAuth scopes. The product page names Falcon Fusion SOAR and optional identity/cloud/mobile/data-protection context plus third-party ingest. Stage 4 is not claimed: native XDR across those domains is documented as requiring additional supported Falcon modules after a platform upgrade, and the dedicated native-XDR article did not return full body on fetch.","sourceIds":["s1","s3","s6"]},"governance":{"score":4,"confidence":"medium","rationale":"Public RTR documentation distinguishes read-only, active-responder and administrator permission levels. Response policies restrict scripts and commands by operating system and assigned host groups; the dedicated RTR Audit API returns session records with optional command logs, user identity and timing. Together these establish the stage-4 permission, audit and action-restriction requirements. The Foundry page is used only for the RTR permission taxonomy, not to credit Foundry or Fusion entitlements. Complete critical-asset safeguards and the full stage-5 operating model are not established by this review.","sourceIds":["s4","s5","s7"]},"operations":{"score":4,"confidence":"medium","rationale":"Public RTR API commands and response-policy documentation provide a remote-operations reference with Windows, macOS and Linux policy differences, including platform-specific script and execution limits. This satisfies anchor 4 without requiring a console-only cheat sheet. A complete public health, restoration and lab path for anchor 5 remains unverified.","sourceIds":["s2","s3","s5"]}},"constraints":["Evaluated software entitlement is Falcon Insight XDR. Falcon Complete MDR, managed threat hunting, and OverWatch are staffed services and are out of cohort.","Native XDR context from identity, cloud, mobile, and data protection is documented as requiring additional supported Falcon modules, not as an automatic Insight-only feature.","Falcon for Legacy Systems, Falcon Insight for ChromeOS, and Falcon for Mobile are separate coverage paths; ChromeOS uses Google event ingest without a Falcon agent.","RTR must be enabled in a per-platform response policy. Several powerful commands (memory dump, Falcon scripts, put-and-run) are Windows-only or Windows/Mac-only in the Terraform schema.","Identity protection requires the sensor on 64-bit Windows domain controllers.","Customer console documentation for detections, Event Search, and RTR UI is not publicly fetchable; scores lean on developer APIs and marketing/FAQ pages.","Do not treat product-page ROI, SE Labs, or MTT* figures as ordinal evidence."],"sources":[{"id":"s1","title":"CrowdStrike Falcon Insight XDR product page","url":"https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-insight-xdr/","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"CrowdStrike Deployment FAQ (sensor OS support)","url":"https://www.crowdstrike.com/en-us/products/faq/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"CrowdStrike Real Time Response API collection","url":"https://developer.crowdstrike.com/api-reference/collections/real-time-response/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"CrowdStrike Foundry RTR Scripts (permission levels)","url":"https://developer.crowdstrike.com/foundry/logic-capabilities/rtr-scripts/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"CrowdStrike Terraform response_policy resource","url":"https://developer.crowdstrike.com/cac/terraform/provider/host-setup-and-management/resources/response-policy/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"CrowdStrike Hosts API collection","url":"https://developer.crowdstrike.com/api-reference/collections/hosts/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Real Time Response Audit API","url":"https://developer.crowdstrike.com/api-reference/collections/real-time-response-audit/","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"sentinelone-singularity-endpoint","cohort":"edr-platforms","edition":"SentinelOne Singularity Complete (endpoint package including Core and Control; not Wayfinder MDR)","asOf":"2026-09-21","status":"research-preview","summary":"Singularity Complete is the paid endpoint package that adds Deep Visibility/EDR, Storyline hunting, remote shell, and advertised 1-click rollback on top of Core NGAV and Control suite features. Rollback is documented as Windows VSS-based; Core vs Control vs Complete must be distinguished. Wayfinder/Singularity MDR is a staffed service and is out of scope.","dimensions":{"maturity":{"score":3,"confidence":"medium","rationale":"Complete product pages document Storyline investigation, kill/quarantine/remediate/rollback, network disconnect, and Full Remote Shell, plus Core/Control/Complete packaging. Stage 4 is not claimed: public pages do not provide a role-gated response matrix, session/command logs, or an OS-specific action table comparable to MDE live response.","sourceIds":["s2","s3","s4"]},"innovation":{"score":null,"confidence":"low","rationale":"The sources describe Storyline, remote response and Windows-oriented rollback, but this pass does not establish a defensible difference from the current EDR baseline across the selected edition. A narrative or rollback marketing description alone is insufficient to assign a beyond-baseline stage.","sourceIds":["s2","s3","s6","s7"]},"breadth":{"score":3,"confidence":"low","rationale":"Core FAQ lists Windows (including some legacy), macOS, and multiple Linux distributions, plus VDI/cloud guests. Complete advertises network block and remote shell. Stage 4 is not claimed: the public macOS list on Core looks stale versus Day-0 marketing, and rollback is documented as Windows VSS-centric. Confidence is low because OS-capability matrices for response are marketing-level.","sourceIds":["s3","s4","s6"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Complete FAQ documents Cloud Funnel replication/export of EDR data to a customer SIEM, Amazon S3, or GCS. That is documented export (stage 2). Stage 3 is not claimed: no bidirectional or automation-capable API was fetched, and Marketplace/Identity/Wayfinder names are adjacent products, not API proof.","sourceIds":["s1","s2","s3"]},"governance":{"score":null,"confidence":"low","rationale":"Fetched Complete and Control pages describe policy-driven response and hierarchical Control policies but do not document RBAC, view-versus-response role split, or analyst-action audit. Stage 2 requires documented role-based access; that evidence is absent, so the score is unknown (null), not 2 and not 0.","sourceIds":["s3","s5"]},"operations":{"score":3,"confidence":"medium","rationale":"Storyline/Deep Visibility blog documents query construction, MITRE indicator search across Windows/Linux/macOS, and saved Watchlists. Complete describes mitigate actions and remote shell at a product level. Stage 4 is not claimed: there is no public remote-ops command reference or rollback restore runbook with OS limits.","sourceIds":["s3","s6","s7"]}},"constraints":["Evaluated package is Singularity Complete (includes Core and Control). Core is NGAV/EPP; Control adds firewall/device control and Rogues. Deep Visibility EDR, remote shell, and extended hunting are Complete-tier in the fetched packaging pages.","Wayfinder MDR / Singularity MDR is a staffed service and is excluded from this software assessment.","Standard historical EDR retention is documented as 14 days, with a paid option up to 365 days; malware/fileless incident retention is separately advertised at 365 days. Confirm the contracted retention, not the marketing maximum.","Rollback is documented on SentinelOne's own explainer as relying on Windows Volume Shadow Copy Service, with snapshots described as every 4 hours and VSS-tamper protection. Do not assume macOS/Linux rollback parity.","Core FAQ Windows Server list on the fetched page stops at 2019 and macOS examples include older releases; treat that list as incomplete pending current agent-release notes (login-gated).","Singularity Identity, Ranger (beyond Rogues), Purple AI, Cloud Funnel destinations, and Marketplace connectors may be extra modules.","No public console RBAC or RemoteOps command matrix was fetched; governance is unknown (null), not a low numeric score."],"sources":[{"id":"s1","title":"Singularity Endpoint Security Platform","url":"https://www.sentinelone.com/platform/endpoint-security/","accessedAt":"2026-09-21","kind":"product"},{"id":"s2","title":"Singularity Endpoint Protection Platform","url":"https://www.sentinelone.com/platform/endpoint-protection-platform/","accessedAt":"2026-09-21","kind":"product"},{"id":"s3","title":"Singularity Complete","url":"https://www.sentinelone.com/platform/singularity-complete/","accessedAt":"2026-09-21","kind":"product"},{"id":"s4","title":"Singularity Core","url":"https://www.sentinelone.com/platform/singularity-core/","accessedAt":"2026-09-21","kind":"product"},{"id":"s5","title":"Singularity Control","url":"https://www.sentinelone.com/platform/singularity-control/","accessedAt":"2026-09-21","kind":"product"},{"id":"s6","title":"What is Ransomware Rollback?","url":"https://www.sentinelone.com/cybersecurity-101/cybersecurity/what-is-ransomware-rollback/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s7","title":"Rapid Threat Hunting with Storylines — Feature Spotlight","url":"https://www.sentinelone.com/blog/rapid-threat-hunting-with-deep-visibility-feature-spotlight/","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"lean-soc","name":"Small security team","description":"A lean SOC needs Plan/SKU-accurate EDR investigation and containment without assuming a staffed MDR service will operate the console.","priorities":["operations","governance","maturity"],"questions":["Which exact paid edition (MDE Plan 2 vs Plan 1; Falcon Insight vs Complete MDR; Singularity Complete vs Core) is on the quote?","Who is allowed to isolate a host or open a live/remote shell, and where are those actions logged?","What is the contracted telemetry retention for hunting versus alert/incident views?"]},{"id":"mixed-os-estate","name":"Mixed Windows, macOS, and Linux estate","description":"Operators must confirm that investigation and disruptive response exist on each planned OS release, not only on Windows workstations.","priorities":["breadth","operations","innovation"],"questions":["For each planned OS version, which response actions are documented: isolate, kill/quarantine, live/remote shell, rollback?","Do servers use a different SKU (Defender for Servers, extra Falcon module, Linux workload SKU)?","If ransomware rollback is a requirement, is it documented for non-Windows hosts in the selected package?"]}],"researchNotes":["Paid EDR software is compared using a current baseline of telemetry, detection, investigation, containment and remote response. Stages describe documented workflows, not efficacy, reliability or market leadership. Public-documentation confidence is at most medium.","Three pilots cover paid EDR-capable software editions; staffed MDR services are excluded. Public developer APIs and edition pages supplement procedural documentation, with evidence limitations recorded per cell.","Each assessment names one paid EDR edition. Adjacent modules and licensing requirements are recorded as constraints and do not silently expand its scope.","Evidence gap: Falcon console documentation and SentinelOne agent-release notes are login-gated. Public developer APIs and edition pages support only the stages recorded here; unsupported permission and operating details remain null.","Scope limitation: Microsoft Defender XDR automatic attack disruption and CrowdStrike native XDR extra-module entitlements sit beside endpoint EDR. They are treated as ecosystem/licensing boundaries, not as free EDR-baseline features.","Microsoft documents that, from 1 September 2026, AIR is no longer a separate or manually triggered investigation experience. Plan 2 live response retains operating-system-specific commands and prerequisites.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","The maturity review also identified a governance correction for Falcon Insight XDR: the public RTR Audit API and response-policy permission restrictions establish anchor 4.0. This is a documented-evidence correction, not a claim of recent product improvement.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."]},"changes":[]}]},"unassessed":[{"slug":"palo-alto-cortex-xdr","name":"Cortex XDR","company":"Palo Alto Networks","profileUrl":"/landscape/vendors/palo-alto-cortex-xdr/"},{"slug":"sophos-endpoint","name":"Sophos EDR","company":"Sophos","profileUrl":"/landscape/vendors/sophos-endpoint/"},{"slug":"trendai-endpoint-security","name":"TrendAI Vision One Endpoint Security","company":"Trend Micro","profileUrl":"/landscape/vendors/trendai-endpoint-security/"},{"slug":"trellix-edr","name":"Trellix EDR with Forensics","company":"Trellix","profileUrl":"/landscape/vendors/trellix-edr/"},{"slug":"bitdefender-gravityzone","name":"GravityZone EDR","company":"Bitdefender","profileUrl":"/landscape/vendors/bitdefender-gravityzone/"},{"slug":"eset-inspect","name":"ESET Inspect","company":"ESET","profileUrl":"/landscape/vendors/eset-inspect/"},{"slug":"withsecure-elements-edr","name":"Elements Endpoint Detection and Response","company":"WithSecure","profileUrl":"/landscape/vendors/withsecure-elements-edr/"},{"slug":"elastic-defend","name":"Elastic Defend","company":"Elastic","profileUrl":"/landscape/vendors/elastic-defend/"},{"slug":"carbon-black-enterprise-edr","name":"Carbon Black Cloud Enterprise EDR","company":"Broadcom","profileUrl":"/landscape/vendors/carbon-black-enterprise-edr/"},{"slug":"arctic-wolf-aurora-endpoint","name":"Aurora Endpoint Defense","company":"Arctic Wolf","profileUrl":"/landscape/vendors/arctic-wolf-aurora-endpoint/"},{"slug":"cisco-secure-endpoint","name":"Cisco Secure Endpoint","company":"Cisco","profileUrl":"/landscape/vendors/cisco-secure-endpoint/"}]}