Looks like others commented too, but to be clear, when you install a Managed EDR/AV, you are giving a company the ability to investigate your machine. Doesn't matter which company it is. We did not just see a random endpoint and go "Let's pull that one's history for giggles."
Signals were generated that lead to an investigation, in this case clearly malicious activity occurring on that endpoint, and in that investigation, it was identified that downloads had occurred, and to identify where they came from and when, the browser history was pulled. In the browser history, was the download data, as well as all the shady shit the threat actor was doing.