People misinterpret how Comodo works and it's combination of different layers. The Protected Objects element of EDR is part of Comodo's core system protection hence the fix for a containment elevated permissions fix with version 12.3.4.8162 where they added Windows Sockets Interface to Protected Files under HIPS/Protected Objects.
With Comodo, it's not about signatures. By default CIS ships with a Light version of the AV database for reduced system resource usage and the signatures with Comodo are more about naming the unknown file because any uknown file will be sandboxed and then checked with File Rating, Viruscope and cloud lookup. You can have it use the full signature base under the Update Settings but there isn't much point given that Comodo will upload and analyse the sandboxed file. Comodo and Xcitium share the same cloud signature base.
You can totally just use Comodo Firewall on it's own as it provides the same level of protection just without the on demand scanning and use whichever AV of your choice though there has been some software conflict with the likes of Kaspersky. The only thing really that full internet security product adds is the on demand virus scanning which is something
@cruelsister has pointed out several times in her videos. You can even run
@Andy Ful 's Hard_Configurator product with CIS or CFW installed though you might get some performance impact because of Comodo's kernel level hooks. I use full CIS because why have the additional 250mb+ ram being used up by Microsoft Defender when CIS sitting in the background is just using 40mb all together.
I'm not the expert here, it works for me and with this latest version bringing naming in line with Xcitium, I'm hopeful that any fixes or changes implemented such as the recent DLL fix in Xcitium will hopefully filter through quicker to the consumer product.