EDR should also allow you do too things such as remote process/memory fingerprints and capture. I've seen ones that allow you to isolate a host from the network and only allow it communicate to the edr controller, you can also do more advanced forensic captures. if it's just doing av it's not edr because the response part is missing.