I chose Eset because it has configurable rules.
Configurable rules allow you to make a hard ban on certain things, whereas the AV must use weights on several detections before it quarantines anything to avoid false positives so that it suites everyone. So you can say when this occurs, definitely stop this because I don't ever do it. This is important, your rules suites your work habits, and anything abnormal to you should be/can be banned. This is the kind of thinking that good security teams do, they detect what is abnormal. Eg, this employee is an office administrative assistant, she never uses powershell. So the security team sits up straight when powershell is used on her PC. When an AV has configurable rules, it can ban powershell and stop it, immediately, before the attack succeeds. Prevent first. There is always a time laspe before a security team can detect.
Powershell, as you know, is very powerful. It can disable security protections, open a hole in your firewall, set up scheduled tasks so that the hackware can contact the attacker's server regularly. Whatever malicious thing you can think of, it can do. Attackers love powershell. Fileless malware love powershell.
Another thing is that configurable rules should have an enable/disable switch. So that, when a sys admin goes to that employee's computer to do some work, he can disable that powershell ban rule temporarily when using the admin account.
I also chose Eset because our previous AV failed to block registry modification in a rule. It has configurable rules, but it is not functioning in our environment. Proving to yourself that a security product works is essential, or your carefully designed security scaffold collapses.
So that's why I chose Eset.