All use cases
    Use case

    Endpoint detection (EDR/XDR)

    Catch attackers on laptops, servers and cloud workloads.

    Why this fits, Endpoint and extended detection platforms: the front line for most security teams.

    92 vendors for this

    Carbon Black (Broadcom) logo
    Carbon Black (Broadcom)
    Endpoint Detection & Response (EDR)
    1 product

    Carbon Black (Broadcom) is an endpoint detection and response platform designed for SOC teams running incident response and threat hunting across hybrid, air-gapped, and offline environments. Acquired by Broadcom from VMware in 2023, it continuously records unfiltered endpoint telemetry from laptops, servers, and cloud workloads, then reconstructs attack kill chains for forensic analysis. Strengths include behavioral EDR, live query and remote response, application control for locked-down systems, and on-prem deployment options that suit regulated industries and customers with strict data residency requirements. Best fit for mature SOCs and existing Broadcom/Symantec customers consolidating endpoint security tooling.

    Continuously records endpoint activity data+11
    Cybereason logo
    Cybereason
    Endpoint Detection & Response (EDR)
    10 products

    Cybereason provides Endpoint Detection and Response (EDR) that correlates endpoint telemetry across machines into MalOp™ narratives, revealing full attack chains from initial compromise to lateral movement. It uses behavioral analysis, machine learning on threat feeds ranked by historical accuracy, and cross-machine correlation for real-time detection of sophisticated threats. The platform supports instant remediation like process termination, file quarantine, persistence removal, and machine isolation. Best for enterprises needing high analyst efficiency (1:200,000 endpoint ratio) and advanced threat hunting without alert fatigue, as validated by top Forrester Wave and MITRE ATT&CK scores.

    Behavioral detection of malicious activity+10
    Darktrace logo
    Darktrace
    Network Detection & Response (NDR)
    8 products

    Darktrace is a network detection and response vendor centered on self-learning behavioral analytics for north-south and east-west traffic. Its NDR product baselines normal activity for users, devices, and segments, then flags anomalous connections, command-and-control behavior, data transfer outliers, and other suspicious network patterns in on-premises, cloud, and hybrid environments. The platform is aimed at teams that need visibility beyond endpoint telemetry and want automated investigation and containment for network-level threats, including encrypted traffic and novel attack paths. Darktrace also sells adjacent security products, but this profile is limited to NDR capabilities.

    Continuously monitors network trafficDetects anomalous network behavior+10
    Fortinet logo
    Fortinet
    Firewall / NGFW
    9 products

    Fortinet’s FortiGate line is the company’s Firewall/NGFW offering, covering stateful firewalling, application control, IPS, web filtering, SSL/TLS inspection, and threat-intelligence-backed blocking. It is widely deployed from branch and edge sites to enterprise perimeter and segmentation use cases, with hardware, virtual, and cloud form factors managed through the same Fortinet policy stack. Buyers typically choose it when they need firewall enforcement plus inline inspection and VPN capability in one appliance, especially in environments that already use FortiGuard threat feeds or the Fortinet Security Fabric. Adjacent products include SD-WAN and ZTNA, but those are not the core scope here.

    Next-generation firewall inspectionIntrusion prevention system+9
    Malwarebytes logo
    Malwarebytes
    Endpoint Detection & Response (EDR)
    1 product

    Malwarebytes delivers Endpoint Detection & Response (EDR) through its EDR Extra Strength solution, available via Malwarebytes for Business Advanced. It focuses on endpoint agent telemetry, behavioral detections, on-host containment, and automated remediation using its patented Linking Engine to remove malware artifacts and process changes. The platform includes a 72-hour ransomware rollback feature for rapid recovery. Malwarebytes EDR is best suited for small to mid-sized businesses with limited cybersecurity staff, offering simplified incident handling and low alert volume. While it also offers adjacent products like patch management and vulnerability assessments, its EDR capabilities prioritize operational efficiency over deep analyst investigation.

    Anomaly detection machine learning for unknown threats
    PRE Security logo
    PRE Security
    Extended Detection & Response (XDR)
    1 product

    PRE Security is an AI-native Predictive SecOps platform designed to help organizations detect, prevent, and respond to cyber threats before they become incidents. The platform combines parserless data ingestion, AI-powered SIEM, Generative XDR, predictive analytics, and agentic automation in a unified security operations environment. PRE Security's AI Data Fabric ingests and correlates data from virtually any security tool without complex integrations, enabling real-time threat detection, investigation, and response. Through natural language interactions and autonomous workflows, security teams can accelerate operations, reduce alert fatigue, and proactively identify emerging risks across their environment.

    Real-time cross-layer correlation of endpoint, identity, email, cloud, and network telemetry using normalized event schemas to detect multi-stage attacks
    Raven logo
    Raven
    Application Security Posture Management (ASPM)
    6 products

    Raven.io provides a runtime application security platform that runs inside cloud-deployed applications to detect and block malicious code execution as it happens, independent of whether a CVE exists. The platform includes application detection and response for forensic visibility down to libraries, functions and call paths, a runtime software composition analysis capability that uses reachability data to de-prioritize vulnerabilities, and a module for discovering and controlling AI agents operating inside application environments. It is aimed at enterprises running internet-facing applications on Kubernetes, containers and compute instances across AWS, GCP and Azure, supporting languages including Java, Python, JavaScript, Go, Ruby, PHP, C++ and .NET. Customers include organizations in regulated industries such as insurance and financial services.

    Runtime exploit prevention+5