# Compare

> Three comparison tables built from one dated data model. The first measures infrastructure and threat-intelligence tools by the layers each one covers; the second measures endpoint detection and response products by what an admin can write a policy on and where the block is enforced; the third measures machine- and AI-agent identity products by what they issue, where they enforce, whether a revocation survives a compromised host, and whether they know anything about the destination. Each row cites the vendor documentation it was read from and the date it was read, and treats a missing capability as absent from that vendor’s documentation rather than tested for.

*Source: https://www.whisper.security/compare*

---

## Whisper Intelligence

|  | Historical DNS resolutions | WHOIS history | SSL / CT | BGP routing | RPKI / MOAS | Physical infra | Actors / ATT&CK | How you query it | Collection | Commercial use |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Whisper Intelligence | covered | covered | covered | covered | covered | covered | covered | Cypher · graph traversal | Passive | Permitted |
| DomainTools | covered (Farsight DNSDB) | covered (20+ yrs) | covered | not covered | not covered | not covered | partial | Guided pivots and IrisQL (Iris) | Mixed | Not published — public WHOIS lookup is CAPTCHA-gated |
| Recorded Future | covered | covered (since 2008, via SecurityTrails) | covered | not covered | not covered | not covered | covered (+ Insikt Group) | NL / cards + SecurityTrails API | Mixed | Not published |
| Silent Push | covered | covered | covered | not covered | not covered | not covered | partial | SPQL · API-only | Active | Community Edition available, feature-limited |
| Validin | covered | covered | covered | not covered | not covered | not covered | partial (framework mappings, not named ATT&CK) | VQL (filter) | Mixed | Community access available, feature-limited |
| WhoisXML API | partial | covered | covered | not covered | not covered | not covered | not covered | REST APIs (32 endpoints) | Passive | Trial credits only; no ongoing free access |
| Spur.us | not covered | not covered | not covered | ASN and prefix context only | not covered | not covered | not covered | — | Mixed | No free Context API access — Monocle is the free product |
| Censys | partial (31+ days, not on Free) | partial | covered | not covered | not covered | not covered | partial (labels) | CenQL (Platform product) | Active | Censys Free available, credit-limited |
| Shodan | partial (history param on /dns/domain) | not covered | covered | ASN and prefix context only | not covered | not covered | not covered | Filters | Active | Not published |
| Cortex Xpanse | not covered | not covered | covered | not covered | not covered | not covered | not covered | — | Active | Not published |
| MS Defender EASM | not covered | partial (registrar + contacts as inventory filters, no history) | covered | not covered | not covered | not covered | not covered | — | Active | Trial available |
| Microsoft Threat Intelligence (Defender XDR / Sentinel) | covered (PassiveTotal heritage) | covered | covered | not covered | not covered | not covered | covered (named actors) | — | Mixed | Included with a Defender XDR or Sentinel licence |
| Maltego | through connectors only | through connectors only | through connectors only | not covered | not covered | not covered | through connectors only | Transforms | Mixed | Community Edition available |
| VirusTotal | covered | covered | covered | ASN and prefix context only | not covered | not covered | partial (needs GTI Enterprise) | VT Intelligence search | Mixed | Free API access, non-commercial use only |
| Pulsedive | partial | covered | covered | ASN and prefix context only | not covered | not covered | covered | Explore (boolean search) | Mixed | Free access, feature-limited |
| Team Cymru (Pure Signal Recon) | covered | covered | covered | covered (NetFlow + ASN) | not covered | not covered | partial (behavioural tags) | Scout QL | Passive | Not published |
| ThreatConnect | through connectors only | through connectors only | through connectors only | not covered | not covered | not covered | covered | TQL | Passive | Not published |
| OpenCTI |  |  |  |  |  |  |  | GraphQL | Passive | Free and open source (Apache 2.0) |
| bgp.tools | not covered | ASN and prefix context only (prefix) | not covered | covered | covered | partial (IXP; PeeringDB not referenced) | not covered | — | Passive | Free only for a personal, non-commercial ASN |
| Kentik | not covered | not covered | not covered | covered | covered (flow-based ROV) | not covered | partial (flags) | AI Advisor (conversational) | Mixed | Not published |
| ThousandEyes | not covered | not covered | not covered | covered (passive via RIPE RIS) | covered | not covered | not covered | — | Mixed | Not published |
| Qrator.Radar | not covered | not covered | not covered | covered | covered (ROA + IRR) | not covered | not covered | — | Passive | Community access available |
| RIPEstat | not covered | covered | not covered | covered | covered (validity) | not covered | not covered | REST calls | Passive | Non-commercial use only; redistribution barred by its terms |
| Cloudflare Radar | not covered | not covered | partial (certificate feed) | covered | covered | not covered | not covered | REST API | Passive | Non-commercial use only under its published licence |

- **Whisper Intelligence** (Passive DNS, WHOIS & domain intelligence): https://www.whisper.security/products/intelligence, 2026-09-20
- **DomainTools** (Passive DNS, WHOIS & domain intelligence): https://www.domaintools.com/blog/supercharge-your-threat-investigations-with-irisql, 2026-09-21
- **Recorded Future** (Passive DNS, WHOIS & domain intelligence): https://www.recordedfuture.com/platform/collection-engine, 2026-09-20. Absorbs SecurityTrails, which the site listed as a second, separate row — Recorded Future finalised into Mastercard 2024-12-20 and SecurityTrails is migrating onto recordedfuture.com.
- **Silent Push** (Passive DNS, WHOIS & domain intelligence): https://www.silentpush.com/platform/, 2026-09-20. Acquired HYAS, announced 2025-12-15.
- **Validin** (Passive DNS, WHOIS & domain intelligence): https://validin.com/, 2026-09-20
- **WhoisXML API** (Passive DNS, WHOIS & domain intelligence): https://main.whoisxmlapi.com/, 2026-09-20
- **Spur.us** (Passive DNS, WHOIS & domain intelligence): https://spur.us/products/context-api/, 2026-09-20
- **Censys** (Attack-surface management (active scanning)): https://censys.com/blog/legacy-search-deprecation/, 2026-09-20. Legacy Search deprecates September 2026; written against the Platform product.
- **Shodan** (Attack-surface management (active scanning)): https://www.shodan.io/, 2026-09-20
- **Cortex Xpanse** (Attack-surface management (active scanning)): https://www.paloaltonetworks.com/cortex/xpanse, 2026-09-20
- **MS Defender EASM** (Attack-surface management (active scanning)): https://learn.microsoft.com/en-us/azure/external-attack-surface-management/, 2026-09-20
- **Microsoft Threat Intelligence (Defender XDR / Sentinel)** (Attack-surface management (active scanning)): https://learn.microsoft.com/en-us/defender-xdr/defender-threat-intelligence, 2026-09-20. Renamed from "MS Defender TI" — the standalone MDTI portal and Intel Explorer retired 2026-08-01.
- **Maltego** (Threat-intel link-analysis & aggregation): https://www.maltego.com/, 2026-09-20
- **VirusTotal** (Threat-intel link-analysis & aggregation): https://docs.virustotal.com/docs/api-overview, 2026-09-20. Runs sandbox detonation and headless-browser URL scanning — not purely passive.
- **Pulsedive** (Threat-intel link-analysis & aggregation): https://pulsedive.com/about/, 2026-09-20
- **Team Cymru (Pure Signal Recon)** (Threat-intel link-analysis & aggregation): https://team-cymru.com/products/pure-signal-recon/, 2026-09-20. The closest fusion competitor: 60+ datasets, including NetFlow, passive DNS, WHOIS and BGP/ASN, over a 90-day window.
- **ThreatConnect** (Threat-intel link-analysis & aggregation): https://www.dataminr.com/, 2026-09-20. Acquired by Dataminr, announced 2025-10-21; threatconnect.com now redirects to dataminr.com.
- **OpenCTI** (Threat-intel link-analysis & aggregation): https://filigran.io/opencti/, 2026-09-20. Whisper ships an OpenCTI connector — an integration, not a competitor. See the integrations page.
- **bgp.tools** (BGP & routing intelligence): https://bgp.tools/kb, 2026-09-20
- **Kentik** (BGP & routing intelligence): https://www.infoblox.com/, 2026-09-20. Acquired by Infoblox, closed 2026-08-06.
- **ThousandEyes** (BGP & routing intelligence): https://www.thousandeyes.com/, 2026-09-20
- **Qrator.Radar** (BGP & routing intelligence): https://radar.qrator.net/, 2026-09-20
- **RIPEstat** (BGP & routing intelligence): https://stat.ripe.net/, 2026-09-20
- **Cloudflare Radar** (BGP & routing intelligence): https://developers.cloudflare.com/radar/routing/, 2026-09-20. A buyer would shortlist it and it was missing from the prior grid entirely — but it carries no WHOIS or ownership layer.

## Whisper Graph XDR

### Sensor & Telemetry

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Single unified agent (EPP+EDR+XDR in one agent) | yes [1] | yes [2] | yes [3] | yes [4] | yes [5] | yes [6] |
| Kernel-independent sensor (user-space / eBPF, no loadable kernel module) | yes [7] | partial [8] | partial [9] | partial [4] | partial [10] | partial [11] |
| Process-execution telemetry (exec + parent-process graph) | partial [1] | yes [2] | yes [9] | yes [12] | yes [5] | yes [11] |
| File-system telemetry (create/modify/rename/delete) | partial [1] | yes [2] | yes [9] | yes [12] | yes [5] | yes [11] |
| Network-connection telemetry (outbound connect) | yes [13] | yes [2] | yes [9] | yes [12] | yes [5] | yes [11] |
| DNS-query telemetry (observing qname) | yes [14] | yes [2] | yes [15] | partial [16] | yes [17] | yes [11] |
| Registry telemetry (Windows) | yes [7] | yes [2] | yes [9] | yes [12] | yes [5] | yes [11] |
| Script / command-line telemetry | yes [1] | yes [2] | yes [9] | yes [12] | yes [5] | yes [11] |
| Real-time memory / injection visibility | partial [13] | yes [18] | yes [19] | yes [20] | yes [21] | yes [11] |
| Measured, calm footprint with a published resource SLA | yes [22] | partial [2] | partial [9] | partial [23] | partial [10] | partial [24] |
| Offline / disconnected protection | yes [22] | yes [25] | yes [9] | yes [4] | yes [5] | yes [26] |
| Tamper protection / anti-uninstall | partial [22] | yes [27] | yes [15] | yes [28] | yes [29] | yes [11] |

### Detection & ATT&CK

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Behavioral ransomware detection (T1486 / T1490) | yes [7] | yes [18] | yes [30] | yes [31] | yes [21] | yes [32] |
| Dropper / event-chain correlation (write → exec → connect) | yes [7] | yes [18] | yes [19] | yes [12] | yes [21] | yes [33] |
| Process injection detection (T1055) | partial [13] | yes [18] | yes [19] | yes [20] | yes [21] | yes [11] |
| Driver-blocklist / BYOVD (T1068) | yes [7] | yes [18] | partial [30] | partial [20] | yes [21] | yes [11] |
| Sigma detection rules | yes [34] | no [18] | partial [35] | partial [12] | partial [36] | partial [33] |
| On-device ML prevention | partial [37] | yes [18] | yes [19] | yes [20] | yes [21] | yes [11] |
| Cloud ML / large behavioral-analytics stack | partial [37] | yes [18] | yes [19] | yes [20] | yes [21] | yes [33] |
| Local, zero-network known-good hash allowlist | yes [38] | partial [39] | partial [40] | partial [41] | partial [21] | partial [42] |
| YARA file / memory scanning | partial [43] | partial [27] | partial [19] | partial [20] | partial [21] | partial [11] |
| JA3 / JA4 TLS client fingerprinting | partial [43] | partial [39] | no [15] | no [16] | partial [17] | partial [44] |
| ATT&CK technique mapping (on-host tactics) | yes [37] | yes [18] | yes [19] | yes [20] | yes [21] | yes [33] |
| Adversary-infrastructure ATT&CK columns (Reconnaissance TA0043 / Resource Development TA0042) from the attacker’s own domains, IPs and certificates | yes [45] | partial [46] | partial [40] | partial [41] | partial [17] | partial [42] |
| C2-infrastructure and exfil-destination reputation at the resolution plane (acts before the connection is made) | yes [45] | partial [46] | partial [15] | partial [41] | partial [47] | partial [44] |
| GenAI SOC assistant (natural-language triage and hunting) | no [14] | yes [48] | yes [30] | yes [12] | partial [36] | yes [33] |
| Validated low-alert / signal-to-noise posture | partial [37] | yes [49] | yes [19] | yes [20] | yes [21] | partial [24] |

### Backend, Analytics & Graph

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Cross-customer telemetry graph | partial [22] | yes [39] | yes [40] | yes [41] | yes [5] | yes [42] |
| Internet-scale naming/routing graph (domains, IPv4/6, ASN, RDAP, certs, passive DNS) | yes [50] | no [39] | no [40] | no [41] | no [17] | no [42] |
| Serves the DNS: graph-first policy resolver the fleet points at | yes [14] | no [2] | no [15] | no [16] | no [47] | no [11] |
| Per-endpoint graph, Cypher/graph-queryable | yes [22] | partial [39] | partial [35] | partial [12] | partial [5] | partial [33] |
| Graph join depth (process → DNS → peer → ASN → actor, across tenants) | yes [45] | partial [39] | partial [35] | partial [41] | partial [5] | partial [33] |
| Finished threat-intelligence program (adversary tracking, human research) | partial [45] | yes [46] | yes [40] | partial [41] | yes [21] | yes [42] |
| Hunting query language | yes [22] | yes [48] | yes [35] | yes [41] | yes [36] | yes [33] |
| Data retention (default window; storage economics) | yes [22] | partial [48] | partial [35] | yes [41] | partial [5] | partial [51] |
| Customer-queryable cross-tenant correlation | yes [45] | partial [39] | partial [40] | no [41] | partial [5] | partial [42] |

### Network & Identity

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Operates authoritative DNS + reverse-DNS (PTR / ip6.arpa) for agent identities | yes [14] | no [2] | no [15] | no [16] | no [47] | no [11] |
| Blocked at DNS resolution | yes [14] | no [2] | partial [15] | no [16] | partial [47] | partial [11] |
| Verifiable per-agent network identity | yes [52] | no [53] | no [3] | no [54] | no [55] | no [56] |
| Per-sub-agent / nested identity (a distinct routable identity per spawned agent) | yes [52] | no [53] | no [3] | no [54] | no [55] | no [56] |
| Directory identity protection | no [52] | yes [53] | partial [3] | yes [54] | yes [55] | partial [56] |
| Per-agent egress / source-bound traffic (agent’s own /128) | yes [57] | no [58] | no [15] | no [16] | no [59] | no [11] |
| Per-agent firewall / byte-metering from the network position | yes [57] | partial [58] | partial [15] | partial [16] | partial [59] | partial [11] |
| Host firewall management (traditional, on-endpoint) | partial [57] | yes [58] | yes [15] | yes [16] | yes [59] | yes [11] |
| Network Detection & Response (NDR) sensor tier | partial [43] | partial [27] | partial [60] | partial [61] | yes [17] | yes [44] |
| Reverse-DNS / RDAP attribution of every outbound flow to an identity | yes [52] | no [53] | no [3] | no [54] | no [55] | no [56] |

### Response & Containment

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Process kill / terminate | yes [62] | yes [27] | yes [30] | yes [12] | yes [29] | yes [63] |
| File quarantine | yes [62] | yes [27] | yes [30] | yes [12] | yes [29] | yes [63] |
| On-host network isolation | partial [62] | yes [27] | yes [15] | yes [12] | yes [29] | yes [63] |
| Off-host containment that holds even when the host OS is owned below the agent | yes [62] | no [27] | no [15] | no [12] | no [29] | no [63] |
| DNS default-deny / resolver-plane containment | yes [62] | no [27] | no [15] | no [12] | no [47] | no [11] |
| /128 revocation / kill-switch on the wire | yes [62] | no [53] | no [3] | no [54] | no [55] | no [56] |
| Remote shell / live response | no [62] | yes [27] | yes [30] | yes [12] | yes [29] | yes [32] |
| Ransomware file rollback | no [62] | partial [27] | no [30] | yes [31] | partial [29] | partial [32] |
| Bounded, safe-by-design response actions (a fixed action set, every one logged) | yes [62] | partial [27] | partial [30] | partial [12] | partial [29] | partial [32] |
| SOAR / automation | yes [14] | yes [27] | yes [30] | yes [12] | yes [36] | yes [32] |
| Managed detection service | no [22] | yes [27] | partial [30] | yes [12] | yes [21] | yes [64] |

### Coverage & Platforms

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Windows sensor | yes [7] | yes [2] | yes [9] | yes [4] | yes [10] | yes [6] |
| macOS sensor | partial [13] | yes [2] | yes [9] | yes [4] | yes [10] | yes [6] |
| Linux sensor | yes [37] | yes [2] | yes [9] | yes [4] | partial [10] | yes [6] |
| Mobile (iOS / Android) | no [22] | yes [2] | yes [9] | partial [4] | yes [10] | yes [6] |
| ChromeOS / agentless ingest | no [22] | yes [2] | partial [9] | no [4] | partial [10] | no [6] |
| Legacy enterprise UNIX (Solaris / AIX / HP-UX) | no [22] | no [2] | no [9] | no [4] | no [10] | yes [6] |
| Containers / K8s / cloud workloads | partial [37] | yes [39] | yes [9] | yes [4] | yes [10] | yes [6] |
| Agent/AI-native: routable identity + governance per spawned AI agent | yes [52] | partial [18] | partial [30] | no [12] | partial [36] | partial [33] |

### Deployment & Footprint

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Cloud SaaS console | partial [22] | yes [2] | yes [9] | yes [65] | yes [5] | yes [26] |
| Self-hosted control plane | yes [22] | no [2] | no [9] | yes [65] | no [5] | yes [26] |
| Air-gapped deployment | yes [22] | no [2] | partial [9] | yes [65] | no [5] | yes [26] |
| MSSP / multi-tenant management | partial [14] | yes [2] | partial [60] | yes [65] | yes [66] | yes [64] |
| Zero-config / one-command onboarding | yes [14] | yes [2] | partial [67] | yes [65] | partial [66] | partial [24] |
| Open-source sensor | yes [1] | no [2] | no [9] | no [4] | no [10] | no [6] |
| Published / transparent pricing | no [22] | partial [68] | yes [67] | no [23] | no [66] | no [24] |

### Independent Validation & Standing

|  | Whisper Graph XDR | CrowdStrike | Microsoft Defender | SentinelOne | Cortex XDR | Trend Vision One |
| --- | --- | --- | --- | --- | --- | --- |
| Gartner Magic Quadrant for EPP standing | no [22] | yes [69] | yes [70] | yes [71] | yes [72] | yes [73] |
| Forrester Wave XDR standing | no [22] | yes [74] | yes [75] | partial [76] | yes [77] | yes [78] |
| MITRE ATT&CK Evaluation entry | no [37] | yes [18] | yes [19] | yes [20] | yes [21] | yes [33] |
| SE Labs / AV-Comparatives / AV-TEST certification | no [22] | yes [49] | partial [19] | partial [23] | yes [79] | yes [11] |
| Production scale (deployed endpoints) | partial [22] | yes [39] | yes [40] | yes [41] | yes [5] | yes [42] |
| Corporate / financial stability | partial [22] | yes [69] | yes [70] | yes [71] | yes [72] | yes [73] |
| Published engineering rigor (mutation-tested code, durability tests run in CI) | yes [80] | n/a [18] | n/a [19] | n/a [20] | n/a [21] | n/a [33] |

1. Whisper's cross-platform telemetry collectors, 2026-08
2. [OS matrix Win/macOS/Linux + Falcon for Mobile (iOS/Android) + Falcon Insight for ChromeOS (agentless, Google event ingest, ChromeOS 113+)](https://www.crowdstrike.com/en-us/products/faq/), 2026
3. [Defender for Identity (SEPARATE product, E5/add-on): sensors on DC/AD FS/AD CS/Entra Connect; behavioral AD/Entra attack detection, not wire identity](https://learn.microsoft.com/en-us/defender-for-identity/deploy/deploy-defender-identity), 2026
4. [Single agent Win/macOS/Linux/K8s; Linux eBPF no-kernel-module, macOS kextless; on-device behavioral AI => offline protection](https://www.sentinelone.com/cybersecurity-101/endpoint-security/endpoint-security-for-linux/), 2026
5. [Cortex Data Lake stitches endpoint+network+cloud+identity; XQL hunting; retention '30-day to unlimited' with 30-day floor, longer sold as capacity](https://cdn.blueally.com/paloguard/datasheets/cortex-xdr.pdf), 2026
6. [Broad OS: Win/macOS/Linux + legacy enterprise UNIX (Solaris/AIX/HP-UX) for server/workload (Deep Security lineage); containers/VMs/OpenShift](https://success.trendmicro.com/en-US/solution/KA-0013185), 2026
7. Whisper's Windows sensor, measured against a reference technique set, 2026-08
8. [Channel File 291 RCA: kernel-mode Windows sensor logic error BSOD'd ~8.5M hosts Jul 19 2024 (evidence a host-resident kernel-coupled agent is itself an availability/attack surface)](https://www.crowdstrike.com/en-us/blog/channel-file-291-rca-available/), 2024-08
9. [Defender for Endpoint on Linux: eBPF now default event provider (no kernel module); positioned for SERVER workloads, not desktop parity](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-linux), 2026-05
10. [Full Linux EDR/ELF analysis needs a kernel module (or user-space mode on kernel 5.0+); unsupported kernels drop to asynchronous mode; narrowest module set](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/9.1/cortex-xdr-agent-for-linux/cortex-xdr-agent-for-linux-requirements), 2026
11. [On-agent engines: ML/AI, behavior monitoring, host IPS with virtual patching (ZDI-fed vulnerability shielding), DLP, app control, device control, C&C callback blocking, web reputation](https://invgate.com/itdb/vision-one-endpoint), 2026
12. [Storyline correlation; kill/quarantine/remediate/rollback/isolate; Network Quarantine (on-host enforced); RemoteOps remote shell + Forensics](https://www.cynet.com/security-foundations/endpoint-security/understanding-sentinelone-edr/), 2026
13. Whisper's macOS sensor, measured against the same set with noted platform limits, 2026-08
14. Whisper's DNS resolver and control-plane design, 2026-08
15. [Network Protection / Web Content Filtering: HOST-enforced block of malicious URLs/domains/IPs by MS reputation; contain via neighboring onboarded Windows devices; host-enforced isolation](https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts), 2026
16. [Firewall Control: manages the native OS HOST firewall (location-aware); not a network/DNS service](https://www.sentinelone.com/blog/feature-spotlight-firewall-control/), 2026
17. [Network Traffic Analysis via Palo Alto NGFW-as-sensor + Cortex broker/Pathfinder feeding analytics (e.g. tunneled-DNS); depends on PAN network stack](https://www.boll.ch/datasheets/Cortex_XDR.pdf), 2026
18. [CrowdStrike-reported 100% detection/protection, zero FP in 2025 MITRE ATT&CK Enterprise eval (vendor framing of un-scored MITRE data)](https://www.crowdstrike.com/en-us/blog/crowdstrike-achieves-100-percent-2025-mitre-attack-enterprise-evaluation/), 2025-12-10
19. [MS-reported 100% technique-level detection + zero FP, 2024 MITRE Enterprise (first round with macOS; eBPF Linux sensor) - vendor framing of un-scored data](https://www.microsoft.com/en-us/security/blog/2024/12/11/microsoft-defender-xdr-demonstrates-100-detection-coverage-across-all-cyberattack-stages-in-the-2024-mitre-attck-evaluations-enterprise/), 2024-12-11
20. [S1-reported 100% detection (16/16 steps, 80/80 sub-steps), zero delays, 88% fewer alerts than median - 2024 MITRE Enterprise (vendor framing)](https://www.sentinelone.com/press/sentinelone-sets-the-standard-with-100-detection-and-88-fewer-alerts-than-median-across-all-vendors-evaluated-in-the-2024-mitre-attck-evaluations-enterprise/), 2024-12
21. [PAN-reported 100% technique-level detection (no config changes, no delays) + 8/10 protection steps blocked with 0 FP - 2024 MITRE ER6 (vendor framing)](https://www.paloaltonetworks.com/blog/2024/12/historic-results-in-the-2024-mitre-attck-enterprise-evaluations/), 2024-12
22. Whisper's own platform overview, 2026-08
23. [Recurring independent reviews: agent can be resource-heavy on low-spec/loaded hosts (esp. during scans); FP-sensitivity historically; steep learning curve](https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/sentinelone), 2026
24. [Reviewer-cited limitations: performance impact, ~600MB installer hard to push to bandwidth-constrained sites, agent-removal difficulty, FPs/alert volume, credit-model confusion](https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/trend-micro/product/trend-vision-one-endpoint-security/likes-dislikes), 2026
25. [Sensor arch: Windows kernel driver, Linux user-space eBPF, macOS Endpoint Security framework](https://thenewstack.io/crowdstrike-a-wake-up-call-for-ebpf-based-endpoint-security/), 2024
26. [SaaS + Sovereign/Private Cloud / on-premises incl. air-gapped/offline; fullest capability set is cloud-hosted](https://www.trendmicro.com/en_us/business/products/deployment-options.html), 2026
27. [Falcon Complete MDR + network containment/isolation, process kill, IOC block, RTR remote shell, USB device control; host-agent-enforced containment](https://www.crowdstrike.com/en-us/services/falcon-complete-mdr/), 2026
28. [Anti-tamper: no uninstall without out-of-band approval](https://howtoharden.com/guides/sentinelone/), 2026
29. [Endpoint isolation (halts all host traffic except to Cortex), process kill, file quarantine, Live Terminal remote shell - agent-enforced on host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/response-actions/isolate-an-endpoint), 2026
30. [Automated Investigation & Remediation + attack disruption (block lateral movement + remote encryption); no native ransomware file-rollback](https://www.microsoft.com/en-us/security/blog/2023/10/11/microsoft-defender-for-endpoint-now-stops-human-operated-attacks-on-its-own/), 2023
31. [Signature ransomware rollback via VSS snapshots (default 4-hour cadence) - WINDOWS-only](https://www.sentinelone.com/cybersecurity-101/cybersecurity/what-is-ransomware-rollback/), 2026
32. [Remote Shell Session (CLI, 2h cap/10min idle) + Run Remote Custom Script; ransomware rollback (Apex One lineage)](https://www.docs.trendmicro.com/en-us/enterprise/trend-vision-one-olh/common-apps/response-management/response-actions/start-remote-shell-s.aspx), 2026
33. [Trend-reported 100% analytic coverage of major steps, 100% sub-steps macOS/Linux/server, 99% overall - 2024 MITRE ER6; notes HIGHER alert volume (vendor framing)](https://newsroom.trendmicro.com/2024-12-11-Trend-Micro-Achieves-100-Coverage-Rate-in-MITRE-ATT-CK-R-Evaluations), 2024-12-11
34. Whisper's Sigma detection-rule engine, 2026-08
35. [Advanced Hunting with KQL; 30-day default raw retention; longer needs Microsoft Sentinel (extra product + cost)](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-overview), 2026
36. [XQL (Cortex Query Language) over xdr_data; XSOAR for automated playbooks](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql/get-started-with-xql/xql-language-features), 2026
37. Whisper's self-run detection evaluation (not a MITRE-run evaluation), 2026-08
38. Whisper's local known-good allowlist, 2026-08
39. [Threat Graph: cross-customer graph of SECURITY TELEMETRY; 40+ PB stored, trillions events/day, ~70M req/sec (not an internet naming/routing graph)](https://www.crowdstrike.com/en-us/blog/how-log-structured-merge-trees-enable-crowdstrike-to-process-trillions-of-events-per-day/), 2024
40. [Microsoft Threat Intelligence: 100T+ signals/day (2025), 1,500+ threat groups incl. 600+ nation-state](https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2024), 2025
41. [Singularity Data Lake: up to 24-month retention, 365 days EDR data OOB (tier/SKU dependent); Deep Visibility + Power Query hunting](https://www.sentinelone.com/platform/data-lake/), 2026
42. [Smart Protection Network: 250M+ sensors, 5T+ threat queries/yr, 15 research centers; product-telemetry reputation feed, NOT an owned internet naming/routing graph](https://www.trendmicro.com/content/dam/trendmicro/global/en/business/technologies/smart-protection-network/ds_smart-protection-network.pdf), 2022
43. Whisper's YARA and TLS-fingerprinting engine, 2026-08
44. [Real NDR tier: XDR for Networks via Deep Discovery Inspector / standalone virtual sensors / TippingPoint IPS; inline blocking + lateral-movement + unmanaged/IoT/IIoT visibility](https://www.trendmicro.com/content/dam/trendmicro/global/en/core/docs/datasheets/ds-xdr-for-networks.pdf), 2026
45. Whisper's ATT&CK technique coverage, mapped from its infrastructure graph, 2026-08
46. [Counter Adversary Operations: 250+ named adversaries, 2,300+ intel reports/yr, ATT&CK-mapped profiles (finished intel/reporting, not a live resolution control point)](https://www.crowdstrike.com/en-us/platform/threat-intelligence/adversary-profiling/), 2026
47. [Can 'restrict network activity / update bad-domain lists' but ONLY through Palo Alto enforcement points (NGFW / DNS Security service) - not a resolver Cortex operates](https://cdn.blueally.com/paloguard/datasheets/cortex-xdr.pdf), 2026
48. [Falcon NG-SIEM/LogScale (Humio): CQL query language, ~7-day default retention extendable to 36 months (paid)](https://www.crowdstrike.com/en-us/blog/falcon-next-gen-siem-top-faqs/), 2026
49. [SE Labs 2025 EPS: 100% Total Accuracy, zero false positives; AV-Comparatives EPR 2024/2025 certified](https://selabs.uk/vendor/crowdstrike/), 2025
50. Whisper's internet-scale naming and routing graph, 2026-08
51. [XDR Data Explorer/OAT default 30 days, extendable to 90/180/365 with a data-retention license; Workbench alerts 180 days](https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-xdr-data-retention), 2026
52. Whisper's per-agent network-identity design, 2026-08
53. [Falcon Identity Threat Protection / ITDR: AD/Entra/Okta directory identity, real-time credential-abuse detection, automated containment (MFA/password reset)](https://www.crowdstrike.com/en-us/platform/next-gen-identity-security/itdr/), 2026
54. [Singularity Identity + Ranger AD (ITDR): real-time AD/Entra attack detection + Hologram deception (directory identity)](https://www.sentinelone.com/platform/singularity-ranger-ad/), 2026
55. [ITDR add-on: directory identity analytics (insider/lateral-movement/credential compromise, AD/Azure AD) - not identity-on-the-wire](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/identity-threat-module-itdr), 2026
56. [Identity telemetry + ASRM (identity posture / account risk), part of zero-trust story - not a routable per-agent wire identity](https://www.helpnetsecurity.com/2024/04/22/trend-vision-one-platform/), 2024-04-22
57. Whisper's per-agent egress design, 2026-08
58. [Falcon Firewall Management: central HOST-firewall policy across Win/macOS/Linux via the agent](https://www.crowdstrike.com/en-us/platform/endpoint-security/falcon-firewall-management/), 2026
59. [Host Firewall module (inbound/outbound rules pushed to agent) + Disk Encryption mgmt + USB Device Control](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Host-firewall), 2026
60. [Device discovery driven by onboarded WINDOWS devices; NOT supported from macOS/Linux sensors; multi-tenant via M365 Lighthouse (historically weak)](https://learn.microsoft.com/en-us/defender-endpoint/device-discovery), 2026
61. [Ranger / Network Discovery: passive/active fingerprinting of IP devices on the LOCAL network (customer's own networks, not the internet)](https://assets.sentinelone.com/iotranger/singularity-network-discovery-en), 2026
62. Whisper's on-host and off-host response design, 2026-08
63. [Endpoint isolation (by IP/hostname) + inline NDR/IPS blocking; host-driven or perimeter-sensor-driven containment](https://docs.trendmicro.com/en-us/enterprise/trend-micro-vision-one-olh/common-apps/response-management/response-actions/isolating-endpoints.aspx), 2026
64. [Vision One for Service Providers: multi-tenant single pane, competitive MSSP pricing](https://www.msspalert.com/news/trend-micro-stands-up-new-service-provider-module-of-vision-one-cybersecurity-platform), 2026
65. [Cloud SaaS + on-prem/self-managed and air-gapped consoles for regulated/isolated environments; strong MSP/MSSP motion](https://www.sentinelone.com/platform/singularity-complete/), 2026
66. [Third-party analysis of Cortex XDR's list and consumption-based pricing](https://underdefense.com/industry-pricings/palo-alto-networks-pricing-ultimate-guide-for-security-products/), 2026
67. [Comparison of Microsoft Defender for Endpoint's published per-user plans](https://agileit.com/news/defender-endpoint-p1-pricing-features-comparison/), 2026
68. [Third-party analysis of CrowdStrike Falcon's published list-price tiers](https://zerometric.net/research/crowdstrike-falcon-pricing-decoded-2026/), 2026
69. [Leader, 2024 Gartner MQ for EPP (5th consecutive); highest Ability to Execute, furthest Completeness of Vision](https://www.businesswire.com/news/home/20240925793981/en/), 2024-09-25
70. [Leader, Gartner MQ EPP - seventh consecutive year (through 2026)](https://www.microsoft.com/en-us/security/blog/2026/05/29/microsoft-is-named-a-leader-in-the-2026-gartner-magic-quadrant-for-endpoint-protection/), 2026-05-29
71. [Leader, Gartner MQ EPP - 6th consecutive year (2026 MQ)](https://www.sentinelone.com/press/sentinelone-named-a-leader-in-the-gartner-magic-quadrant-for-endpoint-protection-platforms-for-6th-consecutive-year/), 2026-05-26
72. [Leader, Gartner MQ EPP - 4 consecutive years (2023-2026)](https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-named-a-leader-in-2026-gartner-magic-quadrant-for-endpoint-protection-platforms/), 2026-05-29
73. [Leader, Gartner MQ EPP - 20th consecutive time (longest Leader streak of any EPP vendor); highest in 3 Critical Capabilities use cases](https://newsroom.trendmicro.com/2025-07-17-Trend-Micro-Celebrates-20th-Consecutive-Recognition-as-a-Leader-in-Gartner-R-Magic-Quadrant-TM-Endpoint-Protection-Platforms), 2025-07-17
74. [Leader, Forrester Wave XDR Platforms Q2 2024 (highest scores Vision/Innovation/Roadmap); continued Leader Q2 2026](https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-named-leader-xdr-independent-research-firm/), 2024-06
75. [Overall Leader, Forrester Wave XDR Platforms Q2 2024; highest Current Offering/Strategy/Market Presence; 15/22 criteria at highest](https://www.microsoft.com/en-us/security/blog/2024/06/03/microsoft-is-named-a-leader-in-the-forrester-wave-for-xdr/), 2024-06-03
76. [Strong Performer (NOT Leader), Forrester Wave XDR Q2 2024 (Leaders were MS/PAN/CRWD)](https://www.sdxcentral.com/analysis/microsoft-palo-alto-networks-crowdstrike-top-forrester-xdr-wave/), 2024-06
77. [Leader, Forrester Wave XDR Platforms Q2 2024](https://www.paloaltonetworks.com/blog/2024/06/forrester-names-palo-alto-networks-a-leader-in-xdr/), 2024-06-03
78. [Leader, Forrester Wave Network Analysis & Visibility (highest current-offering score of 12); also XDR Wave Leader](https://www.malaymail.com/news/money/mediaoutreach/2025/10/22/trend-micro-named-a-leader-in-network-analysis-and-visibility/420835), 2025-10-22
79. [AV-Comparatives EPR 2025: 99% prevention + 99% response; Strategic Leader multiple years](https://www.paloaltonetworks.com/blog/security-operations/cortex-xdr-is-the-only-endpoint-security-market-leader-to-achieve-99-in-both-threat-prevention-and-response-in-avc-epr/), 2025
80. Whisper's published test suite and mutation-testing results, 2026-08

## Whisper Graph XDR — agent and endpoint identity

### The identity itself

|  | Whisper | Idira | Entra Agent ID | Corsha | Teleport | Okta | Aembit |
| --- | --- | --- | --- | --- | --- | --- | --- |
| Issues an identity to the workload or agent | yes | yes | yes | partial | yes | yes | partial |
| Attests what the workload is before issuing | no | yes | not described in their documentation | partial | yes | not described in their documentation | yes |
| A distinct identity per sub-agent, with its lineage recorded | yes | partial | partial | no | not described in their documentation | not described in their documentation | not described in their documentation |

### Where the decision is enforced

|  | Whisper | Idira | Entra Agent ID | Corsha | Teleport | Okta | Aembit |
| --- | --- | --- | --- | --- | --- | --- | --- |
| In the network path, not only at the application | yes | no | partial | yes | partial | no | yes |
| Revocation that holds when the host is compromised | yes | partial | partial | yes | yes | partial | partial |

### What it knows about the other end

|  | Whisper | Idira | Entra Agent ID | Corsha | Teleport | Okta | Aembit |
| --- | --- | --- | --- | --- | --- | --- | --- |
| The destination's owner, network or jurisdiction | yes | not described in their documentation | partial | not described in their documentation | not described in their documentation | not described in their documentation | not described in their documentation |

### Credential operations

|  | Whisper | Idira | Entra Agent ID | Corsha | Teleport | Okta | Aembit |
| --- | --- | --- | --- | --- | --- | --- | --- |
| Rotates or injects credentials in the systems you already run | no | yes | not described in their documentation | not described in their documentation | partial | yes | yes |
| AI agents named in the vendor’s own documentation | yes | yes | yes | no | partial | yes | yes |

- **Whisper** (Whisper Graph XDR — agent and endpoint identity): https://www.whisper.security/products/graph-xdr, 2026-09-20
- **Idira** (Idira (Palo Alto Networks) — Secure Workload Access and Secure AI Agents): https://www.paloaltonetworks.com/idira/agentic, 2026-09-20. The former CyberArk estate, rebranded under Palo Alto Networks in 2026.
- **Entra Agent ID** (Microsoft Entra Agent ID with Global Secure Access): https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id, 2026-09-20
- **Corsha** (Corsha — machine identity for OT and critical infrastructure): https://docs.corsha.com/components/corsha-gatekeeper/, 2026-09-20
- **Teleport** (Teleport Machine & Workload Identity): https://goteleport.com/docs/machine-workload-identity/introduction/, 2026-09-20
- **Okta** (Okta for AI Agents and Okta Privileged Access): https://www.okta.com/blog/ai/okta-for-ai-agents-general-availability/, 2026-09-20
- **Aembit** (Aembit Workload IAM): https://docs.aembit.io/get-started/how-aembit-works/, 2026-09-20
