Endpoint detection and response (EDR) products remain in demand despite the rise of extended detection and response (XDR), according to a recent Forrester report which found CrowdStrike, Microsoft, and Trend Micro are leading the EDR market.

The report evaluated 15 EDR vendors across 20 criteria, including threat hunting, response, and detection capabilities, endpoint telemetry, market approach, planned enhancements, customer counts, and revenue. And according to Forrester analyst Allie Mellen, CrowdStrike stood above the rest.

“​​Its strategy stays true to its DNA as an endpoint-first security tool while methodically expanding into XDR and embracing zero trust,” she wrote, adding that CrowdStrike’s EDR service offers “​​a context-rich UI infused with high-quality, in-depth threat intelligence.”

However, analysts called out the service for its limited data retention, which defaults to seven days. Competing vendors, like Microsoft and Trend Micro, both default to 30 days. The product, according to Mellen, is best suited for security teams looking for a powerful EDR tool with high-quality threat intelligence or those planning to outsource some capabilities to managed service providers.

Microsoft was another powerhouse in EDR identified in the report. It tackles endpoint security with a combination of prevention, detection, and automated remediation. But, while analysts highlighted the company's platform for being able to schedule queries, it called it out for failing to support custom detection rules based on a hunt.

According to Mellen, Microsoft’s product is a better fit for users with large Windows deployments or those moving to an Office 365 E5 license.

Trend Micro’s products — which focus on a cycle of attack surface discovery, risk assessment, and security application — fell prey to similar criticism as Microsoft. Its EDR platform also failed to orchestrate response across multiple endpoints, analysts pointed out.

However, the company's customers highlighted the interoperability with the rest of its portfolio as a key differentiator, according to the report.

“Trend Micro is best suited for security teams that want to focus on detection and response while keeping detection engineering and reporting separated in the SIEM,” Mellen wrote.

Beyond those three leaders, Forrester named Bitdefender, SentinelOne, Palo Alto Networks, Elastic, VMware Carbon Black, and Sophos as Strong Performers; Cybereason, FireEye, and McAfee as Contenders; Fortinet, BlackBerry Cylance, and Check Point Software Technologies as Challengers.

EDR Demand Remains Despite XDR Hype

Even though more EDR vendors are joining the XDR wave, “this is at odds with client needs,” Mellen argues. 

“EDR vendors are focusing on product strategies that leave EDR behind in favor of what is either in process or, for some, comes next: XDR,” she wrote in a blog post. However, “there are still meaningful gains to be made in EDR, specifically, features that improve analyst workflow while prioritizing resilience and providing customization for investigation, response, and threat hunting.”

Because of this, analysts recommended choosing an EDR product or vendor that provides relevant and streamlined context for analyst functions, allows customizable orchestration and automation for response, and has a clear product vision and a strong path to execution.