I have my doubts, but that's at least what they give as the reason for the kernel-level access of EDR tools.