Comment Re:Shocked (Score 1) 24
Easy: Regulatory controls. In many environments, you get a 250+ page spreadsheet with hundreds to thousands of controls on them. There are some vendors like Crowdstrike which fill a niche that nobody else does, as they don't sell an "antivirus". So, it is either buying Crowdstrike, writing a POAM why you didn't use Crowdstrike, or taking the hit why you delibrately didn't buy Crowdstrike or something similar.
It would be nice if OS makers could put the functionality of Crowdstrike as a layer in the OS, perhaps with some standard APIs for monitoring tools and a remote management plane of the MDR layer (be it cloud or local servers), it would be very helpful. Not just an AV program that has a scanner like ClamAV, but something that runs and intercepts. Ideally, the OS would run stuff in a hypervisor, and the tool would run at the hypervisor level, so nothing the OS level can do can affect it.
There are a lot of tools that are the only game in town. Crowdstrike is one of them for the most part, although there are others popping up. I wouldn't be surprised when Crowdstrike's functionality becomes part of Windows Defender.