Try our new research platform with insights from 80,000+ expert users

Cortex XDR by Palo Alto Networks vs CrowdStrike Falcon comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 30, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Organizations see reduced incidents, cost savings, and improved security with Cortex XDR, enhancing compliance and user satisfaction.
Sentiment score
7.5
CrowdStrike Falcon enhances efficiency, reduces costs, and boosts productivity with improved security, providing a valuable return on investment.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
 

Customer Service

Sentiment score
6.5
Cortex XDR's customer service is mixed, praised for efficiency but criticized for slow response and high costs in some areas.
Sentiment score
7.1
CrowdStrike Falcon offers responsive support, though improvements in response time and personalization are noted; premium support is highly praised.
Every vendor has similar support; it depends on how the case is handled and raised.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
 

Scalability Issues

Sentiment score
7.6
Cortex XDR excels in scalability, supporting diverse organizations with seamless cloud management and efficient deployment across various environments.
Sentiment score
7.9
CrowdStrike Falcon is highly scalable, supporting thousands of endpoints with easy deployment, catering to diverse business environments effectively.
When it comes to scalability, it is entirely based on premium models according to demand.
 

Stability Issues

Sentiment score
8.1
Cortex XDR is stable and reliable, with improved performance over time, despite occasional database challenges and false alerts.
Sentiment score
8.2
Users praise CrowdStrike Falcon's stability, performance, and reliability, noting minimal issues and high stability ratings despite occasional integration hiccups.
Cortex XDR is stable, offering high quality and reliable performance.
I have never seen instability in the CrowdStrike tool.
 

Room For Improvement

Cortex XDR requires enhancements in customization, integration, efficiency, threat detection, pricing, and support to address enterprise challenges.
CrowdStrike Falcon needs system integration, UI, reporting improvements, and enhanced compatibility, addressing false positives, support, and pricing concerns.
Cortex XDR could improve its sales support team, including better commission structures and referral programs.
Threat prevention should be their first priority.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
It would be helpful if there were cost-cutting measures.
 

Setup Cost

Cortex XDR pricing is viewed as flexible by some, but others find it expensive, varying by usage and features.
CrowdStrike Falcon's pricing, typically $50,000 to $100,000 annually, is competitive with customizable options and offers free trials.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
 

Valuable Features

Cortex XDR offers advanced endpoint security, integration, AI threat analytics, user-friendly interface, scalability, and low resource consumption.
CrowdStrike Falcon offers robust threat detection and prevention with user-friendly interface, AI-driven analysis, and excellent integration features.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The moment the user clicked on the file, it was quarantined thanks to CrowdStrike.
CrowdStrike provides a lot of visibility in their tool.
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Ranking in Endpoint Protection Platform (EPP)
4th
Ranking in Extended Detection and Response (XDR)
7th
Ranking in Ransomware Protection
2nd
Ranking in AI-Powered Cybersecurity Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
89
Ranking in other categories
No ranking in other categories
CrowdStrike Falcon
Ranking in Endpoint Protection Platform (EPP)
3rd
Ranking in Extended Detection and Response (XDR)
1st
Ranking in Ransomware Protection
1st
Ranking in AI-Powered Cybersecurity Platforms
1st
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
125
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Identity Management (IM) (6th), Threat Intelligence Platforms (2nd), Endpoint Detection and Response (EDR) (1st), Active Directory Management (2nd), Attack Surface Management (ASM) (1st), Identity Threat Detection and Response (ITDR) (3rd)
 

Mindshare comparison

As of February 2025, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 11.0%, down from 14.6% compared to the previous year. The mindshare of CrowdStrike Falcon is 23.8%, down from 29.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms
 

Featured Reviews

Mohammad Qaw - PeerSpot reviewer
Perfect correlation and XDR capabilities for network traffic plus endpoint security
The solution should force customers to integrate with network traffic to see the full benefits of XDR. If you are not integrating it or feeding in your network traffic, then you are just buying a normal antivirus which doesn't make any sense. You are paying double the price to use the antivirus feature or to say you have XDR, but in reality you are not using it. The solution should include an on-premises option because some customers want only on-premises. It would be hard, but good to do if possible. Open XDR would be beneficial in the future. Right now, the solution is Closed XDR so cannot communicate with the few new vendors in the Open XDR market.
Chintan-Vyas - PeerSpot reviewer
Easy to set up with good behavior-based analysis but needs a single-click recovery option
Most organizations are currently looking for a scheduled scan to meet their compliance needs. Other players like Symantec and Trend Micro, FireEye, et cetera, are still providing the signature-based regular scheduled scans also, which is not available in CrowdStrike. That is one parameter that we feel should be there in CrowdStrike. CrowdStrike is only working on the dynamic or the files under execution. CrowdStrike is not scanning the static files. The product could be more accurate in terms of performance. We'd like to have a single-click recovery option. With some machines getting corrupted by malware, we need an easy way to start with a blank slate if things happen. That one feature should be there in the EDR.
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
838,533 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
9%
Government
8%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is the intelligence modules feature. I also find that Crowdstrike Falcon’s dashboard...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon, CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. CrowdStrike Falcon and other solutions. Updated: February 2025.
838,533 professionals have used our research since 2012.