Endpoint Security
Endpoint is the most mature and most concentrated domain in cybersecurity, a late-stage oligopoly in which three vendors hold roughly half the market. CrowdStrike's July 2024 global outage demonstrated both the reach and the fragility of a single agent running on every machine. This page expands on the endpoint-security domain within Vendors.
What endpoint security is
Endpoint security protects the devices where work happens — laptops, servers, mobile, and increasingly cloud workloads and containers — via a lightweight agent that prevents, detects, and responds to attacks. The category evolved through three eras, and the era a vendor operates in shapes its multiple:
- EPP (prevention): signature- and ML-based malware blocking — the legacy "antivirus" layer. Commoditized; price-competitive; near-zero growth premium.
- EDR (detection & response): records endpoint telemetry, detects behavioral attack patterns, and enables analyst response. The category CrowdStrike defined and the value center of the modern agent.
- XDR (extended): correlates endpoint with identity, cloud, email, and network telemetry into one detection fabric — the wedge by which the endpoint agent becomes the platform's nervous system.
The endpoint agent is a valuable position in security because it sits on every device and generates the richest behavioral telemetry. The vendor that owns the agent owns the data that trains the detection models and feeds the SOC — which is why endpoint vendors (CrowdStrike) became platform companies, not the other way around.
How each actor makes money and how they differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| CrowdStrike | CRWD | Platform / buyer | Single-agent Falcon + module land-and-expand; ~120%+ net retention; the modern benchmark — endpoint as platform on-ramp |
| Microsoft | MSFT | Bundler | Defender for Endpoint bundled into E5; competes on price-to-zero, not features — the structural threat to every standalone |
| SentinelOne | S | Independent challenger | Autonomous/AI-led agent; the scaled #3, perennially discussed as a take-private/strategic candidate |
| Palo Alto (Cortex XDR) | PANW | Platform / buyer | Endpoint as a feeder into the XSIAM SOC platform, not a standalone P&L |
| Sophos | Thoma Bravo | Sponsor consolidator | EPP/EDR + MDR; acquired Secureworks (~$859M, 2025) for Taegis + services scale (see 06a) |
| Trend Micro | 4704.T | Independent | Broad platform; reportedly explored a sale — a scaled potential target |
| Trellix | STG | Sponsor-held | McAfee+FireEye merger; legacy base, services-heavy |
| Cybereason, Bitdefender, Trend, Tanium, Trellix | various | Sub-scale / niche | Sub-scale EDR = consolidation targets; Tanium owns endpoint management+security adjacency |
The competitive picture: CrowdStrike and Microsoft are the gravity wells — one through product strength and net retention, the other by bundling endpoint to near-zero inside E5. SentinelOne is the swing asset — the only scaled independent left, which makes it both the most-discussed strategic target and the hardest to value. Vendors below the top three are consolidation targets, because sub-scale EDR cannot out-invest the leaders on detection models or absorb Microsoft's price pressure.
Endpoint market share
Signature deals & events
- Thoma Bravo: Sophos → Secureworks (~$859M, 2025) — merged a sponsor-owned EPP/MDR vendor with a public SIEM/services asset for Taegis scale; the endpoint-plus-services consolidation play.
- CrowdStrike tuck-ins (Adaptive Shield, Flow Security, Bionic) — buying identity/cloud/ASPM modules to extend the Falcon agent beyond endpoint.
- The July 2024 CrowdStrike outage — a faulty Falcon content update crashed ~8.5M Windows machines globally; the defining lesson in single-agent systemic risk, and a recurring diligence question on agent change-management.
- SentinelOne — perennial take-private / strategic chatter — the scaled independent that the market repeatedly games out as the next big endpoint deal.
- Glow — $180M out of stealth at a $1.2B valuation (Jul 22, 2026) — a new venture-scale entrant positioned on a prevention-first approach to securing endpoints in the age of AI agents, led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures. Its founders — CEO Roi Tiger (previously VP of Engineering at Meta), CTO Omer Singer (previously head of cybersecurity strategy at Snowflake), and VP of R&D Ophir Arie (previously VP of R&D at Claroty) — put a well-capitalized startup into a category defined by CrowdStrike and Microsoft. The size of the raise and the entry valuation illustrate that investors still fund new endpoint challengers where an AI-era reframe of the agent is the pitch, even against two gravity wells. Sources: SecurityWeek, Jul 22 2026 · Help Net Security, Jul 22 2026.
The bear case
The endpoint bull case is that the agent is the platform. The bear case is that Microsoft bundles the agent to zero: if Defender for Endpoint is "good enough" and free inside E5, the standalone EDR premium compresses to the security-first, multi-OS, and high-assurance buyer only, and the long tail collapses faster than the leaders can roll it up. A test of the thesis is CrowdStrike's net retention and new-logo growth against Microsoft's Defender attach inside E5. If Microsoft's bundled share keeps climbing while CrowdStrike's net-new logo growth slows, the agent-as-platform thesis is being commoditized from below.
→ Cross-references: Vendors, Identity, Thoma Bravo, Earnings, Bear Case.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.