Why this is its own category
Devices left the company network, and not everywhere was securing them thought through first. Most attacks now use techniques like lateral movement and island hopping: they do damage through tools that are already permitted on the machine. A scanner comparing files against a list sees none of it.
What these products do differently
VMware Carbon Black and Microsoft Defender read system events to learn what normal activity looks like in an estate. What stands out is then not the file but the sequence: why is this Office document starting PowerShell.
Much of the value is in the recording. After an incident you can reconstruct what happened, and that is the difference between “we had something” and “we know what we had”.
The question that actually matters
Which of the two fits is usually settled by existing licensing rather than by detection rates. The harder question comes after: who is looking. EDR with nobody assigned to it is a data store.