However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.
I'm more curious about the case if your org is a few thousand people and you receive random low-effort attacks distributed across those people, will endpoint protection be a panacea?
The examples shown were behavior based, not hash based. It didn't look up a file in a dictionary, it detected priviledge elevations and such.
No product is perfect, but if you have a need to be protected (especially if you are at risk from adversaries such as in banking, health care, government work, or against corporate espionage) I'm quite confident in saying that you're much better off with it than without.
The same company would also, at random times, attempt to phish us or send us fake emails to get us to click on links, to help educate us on the kinds of threats our customers faced I consider myself fairly savvy, and even I fell for one of them.
I ended up leaving for a variety of reasons, but "losing faith in the product" was not one of them.