Atlas Fold / EDR

EDR, unfolded.

Endpoint detection & response

Atlas Fold / EDR / First edition

Endpoint detection & response

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Comparable paid EDR-capable endpoint detection and response software; exclude staffed MDR services.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Microsoft Defender for Endpoint Plan 2 (medium confidence) has the highest documented score (4.6) for Operational maturity among assessed offerings in this comparison group.

Microsoft Defender for Endpoint Plan 2 (medium confidence) and Falcon Insight XDR (medium confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings. 1 offering remains unknown for this dimension.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Microsoft Defender for Endpoint Plan 2: no unknown dimensions.
  • Falcon Insight XDR: no unknown dimensions.
  • Singularity Endpoint: Shipped innovation, Governance & control

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Microsoft Defender for Endpoint Plan 2 · Microsoft

Microsoft Defender for Endpoint Plan 2 (not Plan 1; server coverage via Defender for Servers / Defender for Endpoint for servers) · Assessed 2026-09-21 · Research preview

Operational maturity

How far does public documentation describe a production-operable EDR operating model for the evaluated paid edition?

How completely public documentation describes a production-operable EDR lifecycle from sensor through investigation and authorized response, including edition and operating-system constraints. Anchors are documented-evidence stages, not observed quality. Missing, gated, or unfetched procedure is unknown (null), never zero.

Plan 2 provides endpoint investigation, hunting and live response with documented OS-specific limits. Server coverage requires an appropriate server entitlement. Standalone and manually triggered AIR ended on 1 September 2026; the documented replacement workflow is reflected in the scope.

Score4.6 / 5.0medium confidence

Rationale and sources

The established stage-4 EDR response model is supplemented by documented device grouping (+0.3) and release from isolation with OS boundaries (+0.3), yielding 4.6. The remaining supervised-automation credit is withheld: standalone AIR transition and XDR/preview features prevent a clean current Plan 2-only claim.

How this score is built

4.0 anchor + 0.6 credited progress = 4.6

Next anchor: 5 — Documentation additionally describes production operating safeguards at scale (device-group or policy rings, automated or policy-driven response with human review or undo, and documented restore of containment) across the evaluated edition's supported platforms.

  • +0.3 · Device groups or response-policy rings across the evaluated platform scope

    Plan 2 device-group procedures match devices by name, domain, tags and OS, rank overlapping groups and assign access. The credit is for controlled device grouping; deprecated standalone AIR is not counted as current automation.

    Create and manage device groups in Microsoft Defender for Endpoint

  • Not credited: 0.4 · Automated or policy-driven response with documented human review or undo

    Not established by this assessment; no credit. This does not establish absence.

  • +0.3 · Documented restoration from containment with platform boundaries

    Manual isolation documents Windows, macOS and Linux limits and a Release from isolation procedure; forced release has separate Windows prerequisites. This establishes restoration with explicit platform boundaries, not universal support for every response action.

    Take response actions on a device

Weights are shared editorial rules for this dimension and anchor interval. They are not measured performance differences.

Constraints

  • Evaluated edition is Plan 2. Plan 1 documents only run AV scan, isolate device, stop and quarantine a file, and file indicators — not EDR timeline, live response, or advanced hunting.
  • Microsoft 365 E5 / E5 Security include Plan 2; servers are licensed separately (Defender for Endpoint for servers / Defender for Servers) with possible dual-license discounts.
  • Live response requires Plan 2, Advanced features enablement, and OS/sensor version floors (for example macOS 101.43.84+, Linux 101.45.13+; down-level Windows Server needs Unified Agent).
  • Live response commands are not equivalent across OS: many Windows-only commands (registry, services, scheduled tasks, isolate-from-live-response on macOS only in the advanced table).
  • As of 1 September 2026, AIR is documented as no longer a separate/manual investigation experience; detection/response moves into the default antivirus stack, with on-demand full AV scan. Do not treat legacy standalone AIR as current.
  • Advanced hunting queries native Defender data for 30 days; portal visibility is 180 days. Longer hunt retention needs Sentinel analytics-tier retention or streaming APIs.
  • Automatic attack disruption, contain-user, GPO/Safeboot hardening, and some IP-containment behaviors are Defender XDR / preview-scoped and may require additional workloads (for example Defender for Identity).
  • Public-docs-only research; no lab validation of detection quality or isolation side effects.
  • The high-value-asset restriction guide depends on the Defender deployment tool marked preview; that procedure earns no GA governance credit in this baseline.

Sources

0–5 rubric anchors

  • 0 — Public documentation states that the evaluated edition does not provide a sensor-through-response EDR operating model (EDR lifecycle explicitly absent or unsupported).
  • 1 — Marketing or overview pages describe endpoint protection or EDR at a high level without operating procedures or edition limits.
  • 2 — Product documentation describes sensor deployment and detection or alert generation for at least one operating system.
  • 3 — Documentation describes investigation of endpoint telemetry plus at least one authorized containment action, with stated edition prerequisites.
  • 4 — Documentation describes a repeatable operating model: role-gated response, session or command logging, and an OS-specific action matrix or equivalent policy split for the evaluated edition.
  • 5 — Documentation additionally describes production operating safeguards at scale (device-group or policy rings, automated or policy-driven response with human review or undo, and documented restore of containment) across the evaluated edition's supported platforms.
Assessed offerings inEDR platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Microsoft Defender for Endpoint Plan 24.6 (medium)3.0 (medium)4.0 (medium)5.0 (medium)4.0 (medium)5.0 (medium)
Falcon Insight XDR4.0 (medium)3.0 (medium)3.0 (medium)3.0 (low)4.0 (medium)4.0 (medium)
Singularity Endpoint3.0 (medium)Unknown3.0 (low)2.0 (medium)Unknown3.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

Paid EDR software is compared using a current baseline of telemetry, detection, investigation, containment and remote response. Stages describe documented workflows, not efficacy, reliability or market leadership. Public-documentation confidence is at most medium.

Three pilots cover paid EDR-capable software editions; staffed MDR services are excluded. Public developer APIs and edition pages supplement procedural documentation, with evidence limitations recorded per cell.

Each assessment names one paid EDR edition. Adjacent modules and licensing requirements are recorded as constraints and do not silently expand its scope.

Evidence gap: Falcon console documentation and SentinelOne agent-release notes are login-gated. Public developer APIs and edition pages support only the stages recorded here; unsupported permission and operating details remain null.

Scope limitation: Microsoft Defender XDR automatic attack disruption and CrowdStrike native XDR extra-module entitlements sit beside endpoint EDR. They are treated as ecosystem/licensing boundaries, not as free EDR-baseline features.

Microsoft documents that, from 1 September 2026, AIR is no longer a separate or manually triggered investigation experience. Plan 2 live response retains operating-system-specific commands and prerequisites.

Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.

The maturity review also identified a governance correction for Falcon Insight XDR: the public RTR Audit API and response-policy permission restrictions establish anchor 4.0. This is a documented-evidence correction, not a claim of recent product improvement.

All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • Paid EDR software is compared using a current baseline of telemetry, detection, investigation, containment and remote response. Stages describe documented workflows, not efficacy, reliability or market leadership. Public-documentation confidence is at most medium.
  • Three pilots cover paid EDR-capable software editions; staffed MDR services are excluded. Public developer APIs and edition pages supplement procedural documentation, with evidence limitations recorded per cell.
  • Each assessment names one paid EDR edition. Adjacent modules and licensing requirements are recorded as constraints and do not silently expand its scope.
  • Evidence gap: Falcon console documentation and SentinelOne agent-release notes are login-gated. Public developer APIs and edition pages support only the stages recorded here; unsupported permission and operating details remain null.
  • Scope limitation: Microsoft Defender XDR automatic attack disruption and CrowdStrike native XDR extra-module entitlements sit beside endpoint EDR. They are treated as ecosystem/licensing boundaries, not as free EDR-baseline features.
  • Microsoft documents that, from 1 September 2026, AIR is no longer a separate or manually triggered investigation experience. Plan 2 live response retains operating-system-specific commands and prerequisites.
  • Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.
  • The maturity review also identified a governance correction for Falcon Insight XDR: the public RTR Audit API and response-policy permission restrictions establish anchor 4.0. This is a documented-evidence correction, not a claim of recent product improvement.
  • All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

EDR platforms

Comparable paid EDR-capable endpoint detection and response software; exclude staffed MDR services.

Find your next idea.

Tip: press / to open search. Escape closes this window.