Best Endpoint Detection & Response (EDR) Software Solutions - Page 7

How Many Endpoint Detection & Response (EDR) Software Products Does G2 Track?

Total Products under this Category: 128

Category Stats (Sep 2026)

  • Average Rating: 4.43/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: BluSapphire OnePlatform (+1.05%) - Among all products in this category, BluSapphire OnePlatform recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Endpoint Detection & Response (EDR) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 12,800+ Authentic Reviews
  • 128+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Endpoint Detection & Response (EDR) Software

G2 Grid® for Endpoint Detection & Response (EDR) Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Sophos Endpoint, Acronis Cyber Protect Cloud, Huntress Managed EDR, ThreatDown, ESET PROTECT, Check Point Endpoint Security, and Arctic Wolf.

Underlying data: [Grid® JSON](https://www.g2.com/categories/endpoint-detection-response-edr/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=sophos-endpoint&focus%5B%5D=acronis-cyber-protect-cloud&focus%5B%5D=huntress-managed-edr&focus%5B%5D=threatdown&focus%5B%5D=eset-protect&focus%5B%5D=check-point-endpoint-security&focus%5B%5D=arctic-wolf)

Fidelis Endpoint

Fidelis Endpoint® is an enterprise-grade Endpoint Detection and Response solution designed to give security teams complete visibility and control over every device across their network. It continuously monitors files, processes, registry changes, and system activity across Windows, Linux, and Mac endpoints, helping analysts detect suspicious behavior early—whether devices are on-premises, in the cloud, or operating remotely across distributed and hybrid environments. The platform combines real-time monitoring with automated response capabilities, allowing teams to isolate compromised devices, halt malicious processes, and quarantine suspicious files without manual intervention. By correlating endpoint activity with internal and external threat intelligence, Fidelis Endpoint identifies known indicators of compromise and emerging attack patterns quickly, significantly reducing the time between detection and containment so threats are stopped before they can spread. When incidents occur, Fidelis Endpoint provides analysts with deep forensic data, including process activity, executed files, scripts, and system-level changes, accelerating root-cause analysis and remediation. Endpoint metadata can be retained for 30, 60, or 90 days, enabling retrospective threat hunting to uncover activity that may have been missed during initial detection. Built-in deception technology adds an additional layer of defense, proactively exposing attackers who attempt to evade standard detection methods before real damage occurs. Fidelis Endpoint runs on a lightweight, scalable single-agent architecture suited to large, fast-growing, and highly distributed organizations, and integrates seamlessly with SIEM, SOAR, and major cloud and technology platforms for broader ecosystem visibility. Fidelis Endpoint can be deployed standalone or as part of the Fidelis Elevate® XDR platform, giving organizations of any size the tools to reduce alert fatigue, accelerate investigations, and detect and respond to post-breach attacks significantly faster than industry benchmarks.

Who Is the Company Behind Fidelis Endpoint?

GoSecure Titan Managed Security Platform

While GoSecure Professional Security Services focuses on finding the problems, GoSecure Titan® Managed Security Services make sure to solve them – making GoSecure your ally to consolidate, evolve & thrive. Our service offering includes: • GoSecure Titan® Managed Extended Detection & Response (MXDR) which offers the best-in-class 15-minute response time from threat detection to mitigate with a solution that identifies, blocks, & reports potential breaches. • GoSecure Titan® Vulnerability Management as a Service (VMaaS) helps defend against the constantly changing threat landscape by continuously identifying critical assets, threats and vulnerabilities and working quickly to remediating threats as they arise allowing businesses to get more value from their security and IT operations. • GoSecure Titan® Managed Security Information and Event Monitoring (SIEM) offers advanced security intelligence, comprehensive incident handling, simplified compliance, scalability, threat intelligence integration, and optimized security operations. • GoSecure Titan® Managed Perimeter Defense (MPD) helps organizations address the challenge of monitoring and managing their firewall infrastructure. Whether a single firewall, or hundreds, GoSecure has the skills and resources to manage any size environment. Operating 24x7x365, the GoSecure Security Operations Center (SOC) provides global coverage to keep your firewalls operating at peak efficiency. • GoSecure Titan® Inbox Detection & Response (IDR) gives every user the ability to test any suspicious email. They can finally stop worrying about missing threats, wasting time wondering what to do, or worrying about “crying wolf” too often. With a simple click, employees now become a united force against phishing. GoSecure Titan® IDR is the perfect solution to remediate the phishing problem. Enhance your organization’s cyber defense capabilities GoSecure Titan® Managed Security Services provides industry-leading response and mitigation speeds, essential in today’s rapidly evolving threat landscape. Our services are designed to keep your business safe and secure, ensuring peace of mind in the face of growing cyber threats.

Average Rating: 3.0/5.0

Total Reviews: 1

How Do G2 Users Rate GoSecure Titan Managed Security Platform?

  • Ease of Use: 3.3/10 (Category avg: 8.7/10)

Who Is the Company Behind GoSecure Titan Managed Security Platform?

  • Seller: GoSecure Inc.
  • Company Website:
  • Year Founded: 2002
  • HQ Location: La Jolla, US
  • Twitter: @GoSecure_Inc
    2,742 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

HarfangLab

HarfangLab is a European cybersecurity platform founded in 2018 that develops a suite of solutions in the cloud and on-premises to prevent, detect, and block cyberattacks: EDR, EPP, and Attack Surface Management tools, enhanced by AI. It is the first EDR to have obtained certification from ANSSI and the German BSI. The platform currently protects workstations and servers for small and medium-sized businesses as well as large accounts and public institutions running under Windows, Linux and macOS.

Who Is the Company Behind HarfangLab?

HP Sure Access Enterprise

Improved protection and user experience for Privileged Access Workstations Cyber criminals target privileged users with spear-phishing and other behavior-based attacks to try and access sensitive data. HP Sure Access Enterprise2 uses endpoint isolation technology to defeat such attacks, protecting your privileged data and securing remote access sessions—even if a PC is compromised–with CPU-enforced micro-virtualization. Your data stays safe and your systems remain available.

Who Is the Company Behind HP Sure Access Enterprise?

  • Seller: HP
  • Year Founded: 1939
  • HQ Location: Palo Alto, CA
  • Twitter: @HP
    1,091,979 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    137,941 employees on LinkedIn®
  • Ownership: HPQ

IBM Security Trusteer Rapport

IBM Security Trusteer Rapport is an advanced endpoint protection solution designed to safeguard users from financial malware and phishing attacks. By leveraging industry-leading technology, it effectively removes malware from desktop devices and prevents users from accessing fraudulent websites. This comprehensive security solution helps organizations reduce costs, enhance fraud detection and prevention, and provide a seamless customer experience. Key Features and Functionality: - Fraud Detection and Prevention: Utilizes global threat intelligence to protect customers from financial malware and phishing attacks. - Malware Removal: Works alongside Trusteer Pinpoint Detect to eliminate persistent desktop malware. - Sensitive Account Protection: Employs AI and machine learning to prevent targeted phishing campaigns and account takeover attacks. - Cost Reduction: Substantially decreases fraud losses related to malware and phishing, as well as post-fraud operational costs through device clean-up. Primary Value and User Solutions: Trusteer Rapport addresses the critical need for robust online security by protecting sensitive user information, such as login credentials, from being compromised by malware and phishing schemes. It enhances fraud detection capabilities, reduces associated costs, and ensures a secure and uninterrupted online experience for customers.

Who Is the Company Behind IBM Security Trusteer Rapport?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    328,202 employees on LinkedIn®
  • Ownership: SWX:IBM

Impulse XDR

Impulse is a fully automated host & network intrusion detection platform. It detects malware from behavioural patterns rather than signatures and enables deeper visibility than legacy tools.

Who Is the Company Behind Impulse XDR?

iVerify Enterprise Mobile EDR

iVerify Enterprise Mobile EDR is a purpose-built mobile endpoint detection and response (EDR) platform designed specifically for mobile architectures — not retrofitted from desktop-first security tools. It delivers OS-level visibility, real-time threat detection, and automated response capabilities across both iOS and Android devices, covering managed fleets and BYOD environments without requiring Mobile Device Management (MDM). At its core, iVerify Enterprise collects continuous OS-level telemetry from iOS and Android devices to uncover threats that MDM and legacy Mobile Threat Defense (MTD) solutions fundamentally cannot detect. As AI accelerates exploit development from weeks to hours, iVerify ensures that a compromised device cannot silently report a clean security posture while attackers move freely through corporate systems. The platform addresses the critical SOC coverage gap where mobile devices — used daily to receive MFA codes, store session tokens, and handle sensitive communications — have historically operated with little to no security visibility. iVerify Enterprise closes this gap by bringing process, file system, crash log, and memory monitoring to mobile endpoints, standing alone without requiring a network VPN. Key threat detection capabilities include proven detections of mass-scale iOS exploit campaigns such as Coruna and DarkSword, behavioral detection across exploit activity, credential theft vectors, and OS-level compromise. High-fidelity alerts are delivered directly into SOC workflows for investigation and response, with near-zero false positives on critical alerts. iVerify Enterprise also provides comprehensive smishing and social engineering protection through its SmishGuard capability. Multifactorial databases identify smishing attacks while privacy protocols ensure messages remain unlinkable to end users on iOS. The platform extends protection to voice-based social engineering (vishing) and URL-less smishing attacks. DNS-based blocking neutralizes phishing infrastructure — including short-lived domains that legacy tools miss — across SMS, messaging apps, and browsers. SIM swap detection is another critical capability: iVerify Enterprise provides near real-time detection of SIM swap activity using device-level cellular signals, with automatic carrier verification via API integration for zero false positives. Alerts are delivered immediately to security teams with no user action required. For application risk management, iVerify provides continuous visibility into apps installed across iOS and Android devices, with automated risk scoring to identify vulnerable, misconfigured, and high-risk applications. It detects risky behaviors, insecure configurations, and third-party SDK exposure, triggering alerts when apps exceed defined risk thresholds. The unified security dashboard serves as a dynamic command center, giving security teams an immediate, intuitive, and actionable view of the entire mobile fleet's security posture. Teams can sort devices by risk score to prioritize remediation, access comprehensive device details including full scan history, downloadable reports, and specific alerts. Response capabilities include MDM-less Conditional Access, which immediately blocks access to corporate systems and applications when a compromised device is detected — even without MDM. The platform integrates with SIEM, SOAR, Microsoft Intune, Cloudflare Zero Trust, Okta, Microsoft Entra ID, and other enterprise security tools, making mobile risk visible and actionable across existing workflows. iVerify Enterprise is trusted by Fortune 500 companies and government organizations worldwide, and is also made available free of charge to journalists and civil society organizations through the iVerify.org initiative.

Who Is the Company Behind iVerify Enterprise Mobile EDR?

  • Seller: iVerify
  • Company Website:
  • Year Founded: 2023
  • HQ Location: New York City, US
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

KeyFocus Web Server

KF Web Server is a free HTTP Server that can host a number of web sites.

Who Is the Company Behind KeyFocus Web Server?

Matrix42 Automated Endpoint Security

Matrix42, the leading provider of workspace management solutions, has entered into a strategic partnership with enSilo and now offers the innovative security company's products exclusively in Central Europe and integrates enSilo into its comprehensive Workspace Management Suite

Who Is the Company Behind Matrix42 Automated Endpoint Security?

  • Seller: Matrix42
  • Year Founded: 1992
  • HQ Location: Frankfurt, Germany
  • Twitter: @Matrix42_global
    1,097 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    626 employees on LinkedIn®

MicroWorld EDR

eScan Enterprise EDR, developed by MicroWorld Technologies Inc., is a comprehensive Endpoint Detection and Response (EDR solution designed to provide advanced cybersecurity for enterprises. It offers real-time protection against a wide range of cyber threats, including malware, ransomware, and zero-day attacks, ensuring the security of organizational endpoints. Key Features and Functionality: - Advanced Threat Detection: Utilizes sophisticated algorithms to identify and neutralize both known and emerging threats. - Real-Time Monitoring: Continuously monitors endpoint activities to detect suspicious behavior promptly. - Behavioral Analysis: Analyzes patterns and behaviors to identify potential threats that may bypass traditional signature-based detection methods. - Centralized Management: Provides a unified dashboard for managing security policies, monitoring threats, and generating reports across all endpoints. - Incident Response: Offers tools for rapid response to security incidents, including isolation of compromised systems and remediation measures. Primary Value and Problem Solved: eScan Enterprise EDR addresses the critical need for robust endpoint security in enterprises by delivering proactive threat detection and response capabilities. It enhances the organization's cybersecurity posture by effectively identifying and mitigating complex threats, thereby reducing the risk of data breaches and ensuring business continuity. The solution's centralized management and real-time monitoring enable IT teams to respond swiftly to incidents, minimizing potential damage and downtime.

Who Is the Company Behind MicroWorld EDR?

Morphisec Keep

Who Is the Company Behind Morphisec Keep?

  • Seller: Morphisec
  • Year Founded: 2014
  • HQ Location: Waltham, US
  • Twitter: @morphisec
    2,300 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    101 employees on LinkedIn®

MVISION EDR

Who Is the Company Behind MVISION EDR?

  • Seller: McAfee
  • Year Founded: 1987
  • HQ Location: San Jose, US
  • Twitter: @McAfee_Home
    41,337 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,630 employees on LinkedIn®
  • Ownership: NASDAQ: MCFE

Nyotron War Room

Whether in DETECT or PREVENT mode, managed by us or you, the Nyotron War Room provides you in-depth details about an attack as it happens: where the attack is happening, if it is spreading to other endpoints, what the nature of the threat is, how it got in, and how it spread.

Who Is the Company Behind Nyotron War Room?

  • Seller: Nyotron
  • HQ Location: Santa Clara, CA
  • Twitter: @Nyotron
    493 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

OpenText Core EDR

Who Is the Company Behind OpenText Core EDR?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,048 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

OpenText Core Endpoint Protection

OpenText Core Endpoint Protection is a cloud-based endpoint security solution that protects devices from malware, ransomware, phishing, and zero-day attacks using AI-driven threat detection and real-time behavioral analysis. Built for simplicity and effectiveness, it replaces traditional, signature-heavy antivirus with next-generation protection that continuously monitors and blocks threats before they can execute. Our solution leverages OpenText global threat intelligence and machine learning to identify both known and unknown threats, reducing infections and minimizing business disruption. Managed through a centralized cloud console, OpenText Core Endpoint Protection allows IT teams and MSPs to deploy, monitor, and control security across all endpoints without complex infrastructure. Pre-configured policies and automation reduce administrative overhead, while seamless integrations with RMM and IT management tools simplify operations. Key benefits: Stronger protection against modern threats – blocks ransomware, malware, and emerging attacks before they impact users Real-time detection and response – identifies and neutralizes threats instantly using behavioral analysis and AI Reduced downtime and disruptions– prevents infections and keeps endpoints running without performance impact Simplified security management – cloud-based control with pre-built policies and minimal maintenance Faster deployment and scalability – lightweight agent enables rapid rollout across environments Supports compliance and cyber insurance – helps meet security standards with consistent policy enforcement OpenText Core Endpoint Protection delivers powerful, next-generation endpoint security that reduces risk, simplifies management, and keeps your business running without interruption.

Who Is the Company Behind OpenText Core Endpoint Protection?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,048 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX
Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated March 4, 2025