The alternative is that everyone in the Microsoft security ecosystem gets off kernel-mode drivers. Once ebpf-for-windows lands, it should be possible for Microsoft, CrowdStrike, and everyone else to run their filters in user-land. That puts everyone on a level playing field, and makes the ecosystem more secure overall.