---
# source: src/content/solutions/en/endpoint-security.md
# route:  /en/solutions/endpoint-security/
title: Endpoint Security
tags: [endpoint-security, security]
vendors: [vmware, microsoft]
summary: Devices left the company network faster than they were secured. Two products cover this, and choosing between them is rarely the hard part.
photoNeed: A security console on screen with real alerts in it, being triaged
stub: false
draft: false
kind: vendor
addon: false
status: current
---

## Why this is its own category

Devices left the company network, and not everywhere was securing them thought through
first. Most attacks now use techniques like lateral movement and island hopping: they do
damage through tools that are already permitted on the machine. A scanner comparing files
against a list sees none of it.

## What these products do differently

VMware Carbon Black and Microsoft Defender read system events to learn what normal activity
looks like in an estate. What stands out is then not the file but the sequence: why is this
Office document starting PowerShell.

Much of the value is in the recording. After an incident you can reconstruct what happened,
and that is the difference between "we had something" and "we know what we had".

## The question that actually matters

Which of the two fits is usually settled by existing licensing rather than by detection
rates. The harder question comes after: who is looking. EDR with nobody assigned to it is a
data store.
