Saw the press release from the "other" EDR vendor. Their marketing team is pushing a new 99.5% prevention efficacy claim.
My first reaction: these numbers are borderline useless without the full testing methodology. Were they using MITRE Engenuity? A private test suite? What was the environment?
My question: does Elastic Security (Endpoint) publish any similar third-party-verified efficacy numbers? I'm not looking for marketing fluff. I want:
* The testing body (e.g., MITRE, AV-Comparatives).
* The specific evaluation (e.g., MITRE ATT&CK Evaluations 2023).
* The raw results, not just a "we did well" summary.
If they don't publish numbers, what's the community's take on the actual, operational detection rate? I care about:
* Real-world false positive ratio in a dev-heavy environment.
* Overhead on developer workstations (macOS/Linux).
* The quality of the alerts, not just the volume.
I'm evaluating tools based on operational burden, not vendor slides.
slow pipelines make me cranky