Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Darktrace comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.4
Automation increased ROI by over $500,000, reduced analyst needs, and improved incident handling, though some are still evaluating.
Sentiment score
7.3
Darktrace's threat prevention boosts security, saves costs, and offers significant value, especially for online businesses, despite quantification challenges.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
 

Customer Service

Sentiment score
6.9
Cortex XSIAM support varies widely, with mixed reviews; premium support receives better feedback due to experienced staff.
Sentiment score
7.6
Darktrace support is praised for its responsive and efficient service, though a few cite improvement areas for complex issues.
It is ineffective in terms of responding to basic queries and addressing future requirements.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The technical support from Darktrace is of high quality.
The response time and quality are satisfactory.
 

Scalability Issues

Sentiment score
7.2
Cortex XSIAM is mostly seen as highly scalable, adaptable, and integrates seamlessly across various enterprises and IT departments.
Sentiment score
7.6
Darktrace is praised for its scalability, efficiently managing large networks with flexible deployment despite cost concerns, excelling in diverse environments.
Without proper integration, scaling up with more servers is meaningless.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
 

Stability Issues

Sentiment score
8.5
Cortex XSIAM is highly stable and reliable, often scoring 10/10, with rapid resolution of occasional update-related issues.
Sentiment score
8.5
Darktrace is highly stable, with users rating it 8-10, citing reliability despite rare minor issues like human error.
The product was easy to install and set up and worked right.
The stability of Darktrace is excellent, rated ten out of ten.
 

Room For Improvement

Cortex XSIAM should enhance context, integration, flexibility, and support while streamlining its pricing and improving incident response automation.
Darktrace needs better integration, a simpler interface, automation enhancements, flexible pricing, improved documentation, and expanded notifications.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Improvements could be made to the dashboard and GUI, making it easier to deploy.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable compared to CrowdStrike.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
There are still some issues with the network capturing or blocking traffic even after implementing exceptions.
The management dashboards and the meter dashboards should be more user-friendly and simple to use for easy management.
 

Setup Cost

Enterprise users find Cortex XSIAM costly, but competitive pricing; extra features and licensing complexity increase expenses.
Darktrace is costly for small businesses but offers flexible plans and pricing varies with devices and modules chosen.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
The product is considered expensive compared to others.
 

Valuable Features

Cortex XSIAM offers strong security orchestration, AI threat mitigation, and competitive pricing, with seamless third-party integration and user-friendly setup.
Darktrace excels in AI threat detection, real-time monitoring, and autonomous response, offering seamless integration and an intuitive interface.
The flexibility for creating manual workflows stands out.
Its signature-less subscriptions and robust detection power stand out in improving threat detection.
Cortex XSIAM is able to detect abnormal behavior of malicious code and subsequently block it.
The features that are most valuable to me include detection, response with analytics, and network detection.
The most valuable features are the AI and advanced learning tools that distinguish it from other products.
Darktrace is valuable since it offers full packet capture and detailed metadata.
 

Categories and Ranking

Cortex XSIAM
Ranking in AI-Powered Cybersecurity Platforms
7th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
11
Ranking in other categories
Security Information and Event Management (SIEM) (17th), Identity Threat Detection and Response (ITDR) (6th)
Darktrace
Ranking in AI-Powered Cybersecurity Platforms
2nd
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
77
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), AI-Powered Chatbots (2nd), Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Attack Surface Management (ASM) (3rd)
 

Mindshare comparison

As of April 2025, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XSIAM is 10.4%, up from 2.5% compared to the previous year. The mindshare of Darktrace is 24.7%, down from 30.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms
 

Featured Reviews

Forrest Stevens - PeerSpot reviewer
A robust security operation that ensures achieving automation, stability, and scalability
There is room for improvement in some areas, and I would highlight three key aspects. Firstly, the Attack Surface Management (ASM) module could benefit from more contextual depth. Currently, it tends to provide a broad overview without enriched context, and there's room for enhancement in this regard. Secondly, further integration capabilities with various other software products that can seamlessly tie into Cortex XSIAM would be advantageous. This would enhance its versatility and interoperability within a broader ecosystem. Regarding performance, there's potential for optimization. When multiple tabs are open in Cortex XSIAM, it can experience slowdowns, leading to longer load times for web pages. It's worth noting that this isn't a severe issue, and it doesn't entail waiting for extended periods, but there is room for improvement in terms of performance optimization.
Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
10%
Government
7%
Computer Software Company
14%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The product is very expensive. Additional integration and support are not provided by Cortex and must be purchased from partners. This adds to the cost and delays projects due to resource dependency.
What needs improvement with Cortex XSIAM?
The standard integrations are very limited, and the integrations available are not listed in the marketplace. Obtaining validation for integrations from Palo Alto takes around eight months, which i...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
 

Overview

 

Sample Customers

Information Not Available
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Find out what your peers are saying about Cortex XSIAM vs. Darktrace and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.