Which protection actually detects the most

Every EDR, AV, DLP and firewall agent found in the published sample, scored on what happened when the machines running it were attacked. This is the table to take to a licence renewal — with its caveats read first.

Read this as “how do machines running X do”, not “X caught it”

A report records which products were installed and what the machine did — it cannot attribute a specific detection to a specific vendor. A machine running both an EDR and an AV contributes its results to both rows. Configuration, licensing tier and policy matter at least as much as the badge on the box, and this sample cannot separate them. Full caveats.

No published reports yet — so no league table

A product needs 3 separate published reports before it is named here. Below that the table would be unfair to the vendor and useless to you, and it would identify the contributor.

What the table will show, per product

The columns this page will show once there are published reports.
ColumnWhat it tells you
Detection rateShare of simulated attacks that were detected on machines running it.
Most-missed techniqueThe single technique that most often walked past it.
Avg posture scoreHow well-configured those machines were overall — context for the rate.
Health mixHow often the agent was healthy, degraded or disabled when tested.
ReportsThe sample size. Small samples are withheld entirely rather than shown small.