They can participate in this test without being an EDR. There is no requirement that the product should be EDR, it should be a business solution. Check Point also tested there and with very high coverage, isn’t an EDR either.
This test simulates techniques, tactics and procedures used in real attacks and focuses on whether block was produced or admin was notified (how much of them are covered).
Blocks can be produced with various components, including but not limited to definitions, behavioural blocking, static analysis and others.
Only for the notification part it makes sense the product to be EDR.
Because Deep Instinct is not, it had much lower coverage than let’s say Sentinel One which is.
I'm actually curious to try a full EDR solution. Another guy from my company bought cylance optics a while back and I watched him test it, but their EPP section left me very unsatisfied (extremely high false positive rate). crowdstrike's EDR is good, but too expensive.
I don't know how to choose, if separate EDR without EPP, I saw Fidelis, and aml sells it (Taiwan reseller where I bought DI), but I can't decide if I really want to choose one without EPP plan.
cybereason? Seems good, they have bitdefender engine and comes with their own machine learning, the mitre test score of EDR is also very good, but I can't find their reseller, if you know their reseller please let me know, thank you very much.