IMHO, the EDR is a good tool for IT to do such a job as forensics.
The generic (old-fashioned) EPP is like HIPS. EDR compares with EPP. EDR is able to show you the context and the topology such as a diagram for an incident.
Some products incorporate AV into the EDR as the basic element.
Considering the budget, some users might choose the AV. EDR is much more powerful than AV when you need forensics. The traditional AV is signature-based and heuristic. EDR leverages more, e.g. Deep Learning…