Manage endpoint detection and response, EDR/XDR platforms, detection rules, and incident investigation. Use when the user asks about EDR, XDR, endpoint detection, CrowdStrike, Defender, SentinelOne, or detection rule.