3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Provide a matrix showing which prevention capabilities your agent enforces on each operating system and version in [OS versions in scope].
Why it matters. Prevention features often differ by operating system. A product that blocks on Windows but only alerts on macOS or Linux leaves those hosts without protection unless the buyer knows to compensate.
Good answer
- Rows list each prevention capability (pre-execution, behavioral, script, exploit, ransomware, device control) and columns list each OS version and architecture, including ARM
- The matrix marks capabilities that run in detect-only mode on a given OS
- The matrix states OS dependencies, such as required kernel modules or system extensions
Red flags
- A single 'supported' mark per OS with no breakdown by capability
- Detect-only behavior on macOS or Linux is not disclosed
- Legacy OS versions in scope are missing from the matrix
2. Provide a mapping of your shipped detection content to MITRE ATT&CK techniques and sub-techniques, broken out by operating system.
Why it matters. Without a technique-level mapping per operating system, the buyer cannot compare coverage against its threat model. Gaps on macOS or Linux stay hidden until an incident.
3. List each exclusion and suppression type your product supports, such as by file path, hash, code signer or command line. For each type, state whether it stops prevention, alerting, telemetry collection, or a combination.
Why it matters. If the buyer cannot tell what an exclusion turns off, an exclusion meant to silence one noisy alert can also stop blocking or stop recording activity on that host. That leaves a blind spot nobody intended.
Capability areas
Prevention & Protection (12)
Pre-execution and behavioral blocking of malware, exploits, scripts and ransomware, prevention policy modes, offline protection, and device control for removable media. Excludes detection-only analytics and post-incident remediation.
Detection Coverage & Content (12)
Behavioral detection of fileless, living-off-the-land and credential-theft techniques, ATT&CK technique mapping, custom detection authoring, and threat-intelligence enrichment of alerts. Excludes false-positive tuning workflow and cross-domain correlation.
False-Positive Management & Tuning (10)
Exclusion and suppression mechanics, scoping of exceptions, tuning workflow against the buyer's own business software, exception review and audit, and controls that keep policies from drifting into audit-only mode. Excludes detection authoring.
Investigation & Threat Hunting (12)
Real-time fleet-wide endpoint search, raw-telemetry retention and query language, process-tree and attack-timeline views, IOC and behavioral hunting, and live forensic collection. Excludes response actions and AI-assisted triage.
Response & Remediation (12)
Host isolation, process and file actions, remote shell, ransomware and malicious-change rollback, remediation without reimaging, and policy-driven automated response with scoped authority. Excludes managed-service response by vendor analysts.
Cross-Domain Correlation & Telemetry Breadth (11)
Ingestion and correlation of identity, email, cloud-workload and network telemetry with endpoint signals, incident grouping, attack-chain reconstruction, identity threat detection, and first-party versus third-party connector depth. Excludes container runtime protection itself.
Agent Footprint, Coverage & Integrity (12)
Agent CPU, memory and I/O overhead on laptops, servers and VDI, OS and architecture coverage including ARM and legacy versions, single-agent versus multi-module design, running alongside an incumbent security agent without conflicts, and tamper protection. Excludes update and rollout controls and the migration project itself (ADM).
Sensor & Content Update Control (10)
Staged, ring-based rollout of sensor versions, detection content and policy changes, buyer control over update timing, halt and rollback mechanics, and agent fail-safe behavior when an update misbehaves. Excludes the vendor's corporate disaster recovery.
Cloud Workload & Container Protection (10)
Runtime protection and telemetry for cloud VMs, containers, Kubernetes nodes and ephemeral workloads, deployment patterns for those workloads, and integration with a separate CWPP. Excludes cloud security posture management.
AI-Assisted Triage & Investigation (9)
AI features that summarize, prioritize, triage and investigate alerts, generate hunting queries, and recommend response, judged by the analyst work they remove on the buyer's data. Excludes generic AI governance, safety and autonomy controls covered by cross-cutting modules.
Managed Detection & Response and SOC Ecosystem Fit (9)
The vendor's own managed detection and response option, response authority granted to vendor analysts, escalation to the buyer, support for third-party MDR providers, and alert and telemetry streaming into SIEM, SOAR and ticketing tools. Excludes generic API and SSO availability.
Fleet Administration & Deployment (9)
Agent deployment and enrollment at scale, policy hierarchy and inheritance, role-based scoping of response actions, multi-site or multi-tenant management, sensor health and coverage-gap reporting, and moving policies, exclusions and groups over from an incumbent product. Excludes the vendor implementation services.
Questions about this package
How many Endpoint Detection & Response (EDR/XDR) RFP questions are there?
128 solution questions in 12 capability areas: 23 for the RFI, 67 for the RFP and 38 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.