Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Cortex XSOAR vs Proofpoint Threat Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
48
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
Proofpoint Threat Response
Average Rating
8.0
Reviews Sentiment
7.7
Number of Reviews
5
Ranking in other categories
Security Incident Response (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Palo Alto Networks Cortex XSOAR is designed for Security Orchestration Automation and Response (SOAR) and holds a mindshare of 9.7%, down 12.2% compared to last year.
Proofpoint Threat Response, on the other hand, focuses on Security Incident Response, holds 15.4% mindshare, up 9.2% since last year.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR9.7%
Microsoft Sentinel16.3%
AWS Security Hub8.3%
Other65.7%
Security Orchestration Automation and Response (SOAR)
Security Incident Response Market Share Distribution
ProductMarket Share (%)
Proofpoint Threat Response15.4%
ServiceNow Security Operations14.4%
IBM Resilient8.8%
Other61.4%
Security Incident Response
 

Featured Reviews

DayaramGoyal - PeerSpot reviewer
Offers automation but requires enhancements for intuitive configuration
Palo Alto Networks Cortex XSOAR is a good product with enhanced and efficient playbooks, as demonstrated during our use case simulations. We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs. The analytics feature in Palo Alto Networks Cortex XSOAR is impressive. The solution is quite exhaustive regarding integrations, with many pre-integrations available, especially for market-leading products. There might be challenges with make-in-India products, as they tend not to build the necessary connectors. This depends on whether you are selling to enterprises or other customers. For government customers, you might encounter many Indian products, such as firewalls, which could pose integration challenges unless you have open APIs. However, for market-leading products, there are ready-made integrations available.
Giuseppe Sgroi - PeerSpot reviewer
Blocks potential spam emails efficiently and integrates well with our security framework
We use the product to verify and manage emails sent and received through our Microsoft Exchange server, focusing on blocking potential spam emails The platform's most valuable include the ability to check emails and block potential spam. The platform's technical support services and pricing need…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information."
"I have found the solution very useful, it integrates well with other platforms."
"We use the solution to automate our SIEM tools and incidents."
"The solution is very reliable."
"It is a scalable solution. I would rate scalability a ten out of ten."
"It was useful as a ticketing tool."
"Cortex XSOAR's most valuable features are the playbooks, custom integration, the machine-learning model, and the layout, classifier, and mapper."
"The product is quite easy to use."
"Support is very responsive."
"It has reduced our manual efforts to remove emails from each user's inbox, and in this case we do not have to ask our IT department or users to do so."
"If something's pulled and then it's later declared a false positive, it will automatically restore. They also take automatic feeds from their advanced threat detection modules."
"The platform's most valuable include the ability to check emails and block potential spam."
"The best part of Proofpoint Threat Response is the Auto-Pull feature. Being able to pull an email back from a user's mailbox is very useful, yet I have noticed that not a lot of organizations use this kind of feature."
 

Cons

"Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners."
"The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a downside."
"It is been decommissioned by Palo Alto."
"Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated."
"The dashboard performance could be improved."
"The price of the solution could be improved."
"In terms of improvement, it needs to be more modular. It's not. When you're working in layouts and you create specific apps within layouts, there's no portability right now in order to reuse that code across multiple layouts. I can't take a tab and say I want to use this tab on these other layouts. I have to physically go in there and recreate it from scratch, which is maddening."
"It is not a very scalable solution."
"The platform's technical support services and pricing need improvement."
"The interface within Threat Response could be made simpler."
"The on-premise version doesn't scale well for large companies."
"If the reporting gets improved then it would be better, but the product is running amazing as it is."
"Has some quirks."
 

Pricing and Cost Advice

"My company did not make any payments towards the licensing costs attached to the product since we were only using its pilot version."
"There is a perception that it is priced very high compared to other solutions."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"It is expensive."
"The solution is a bit on the expensive side."
"Palo Alto offers significant discounts to customers who purchase the products repeatedly."
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"Cortex XSOAR's price could be lower."
"The way most big companies work with Proofpoint is that they try to tie everything into an enterprise license. I can't comment on the actual costs, however I do know that alternative solutions such as Abnormal Security can be much more expensive than Proofpoint Threat Response."
"It's quite affordable to have it with this much functionality and ease to administrate."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
867,497 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
11%
Manufacturing Company
9%
Government
7%
Healthcare Company
11%
Computer Software Company
11%
Energy/Utilities Company
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise24
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
What is your experience regarding pricing and costs for Proofpoint Threat Response?
I have a vague idea because I don't know what others are charging. But we felt that putting up with the pains and having to spend more time keeping it running than we expected is still better than ...
What needs improvement with Proofpoint Threat Response?
The platform's technical support services and pricing need improvement.
What is your primary use case for Proofpoint Threat Response?
We use the product to verify and manage emails sent and received through our Microsoft Exchange server, focusing on blocking potential spam emails.
 

Also Known As

Demisto Enterprise, Cortex XSOAR, Demisto
No data available
 

Overview

 

Sample Customers

Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
University of Waterloo, Akorn, Fenwick and West LLP
Find out what your peers are saying about Microsoft, Palo Alto Networks, Splunk and others in Security Orchestration Automation and Response (SOAR). Updated: August 2025.
867,497 professionals have used our research since 2012.