what part of EDR software seems malicious to you?
"Thankfully" it seems they did a progressive rollout of whatever version of Defender that detects our software so we didn't get every customer angry at once, which would come pretty close to a business ending event.
So yeah malware seems an adequate word to me. Especially since there's no way to find out what heuristic we're tripping and no one to ask for help so there's no guarantee that this won't happen again in a few weeks.
Threats are not simply viruses, and network detection / response is objectively different.
You also probably connect your "standalone system" to a network.