Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Cortex XSOAR vs SentinelOne Singularity Complete comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.4
Palo Alto Networks Cortex XSOAR enhances ROI through automation, integration, and efficient mature SOC processes, reducing investigation time.
Sentiment score
7.6
SentinelOne Singularity Complete enhances efficiency and security, reducing response time, costs, and incidents while increasing productivity and savings.
 

Customer Service

Sentiment score
6.0
Palo Alto Networks Cortex XSOAR support is knowledgeable but varies in response times and service quality, needing possible improvements.
Sentiment score
7.3
SentinelOne's support is praised for efficiency, expertise, and responsiveness, despite occasional slow responses and non-interactive communication.
They do a great job of figuring out the problem and pointing you to generic documentation or working with you to fine-tune a solution.
SentinelOne's policy required the MSP to contact their company and schedule the deactivation at least 24 hours before.
 

Scalability Issues

Sentiment score
7.4
Palo Alto Networks Cortex XSOAR is scalable, integrating well with APIs, though large deployments may face challenges and latency issues.
Sentiment score
8.1
SentinelOne Singularity Complete enables seamless scalability and integration, supporting global enterprises with effective endpoint protection and management.
The tool's built-in automation for deploying the agents works well for large infrastructures like mine.
My deployment is relatively small, and SentinelOne Singularity Complete works within those constraints.
 

Stability Issues

Sentiment score
7.8
Palo Alto Networks Cortex XSOAR is stable and reliable, though minor bugs occur during updates and with oversized storage environments.
Sentiment score
7.9
SentinelOne Singularity Complete is praised for stability, effective performance, and reliable updates, with occasional third-party software conflicts.
It has caused problems with interoperability between third-party tools, which could lead to entire servers crashing or specific tools failing.
This indicates room for improvement in stability when interacting with other solutions.
 

Room For Improvement

Cortex XSOAR requires easier setup, better IoT support, improved UI, more connectors, flexible pricing, and enhanced documentation.
SentinelOne Singularity Complete needs console improvements, better integration, clear documentation, efficient updates, and enhanced automated threat responses.
The deployment requires integration and the development of integration modules.
The only thing that prevented the attack from succeeding was a free version of Malwarebytes.
It's challenging to prevent a user from manipulating their privileges or someone else's of others, and it's difficult to control what users can access at the organizational level.
 

Setup Cost

Cortex XSOAR is seen as expensive yet valuable for security, with variable pricing and discounts post-Palo Alto acquisition.
SentinelOne Singularity Complete balances higher costs with robust endpoint protection, justifying prices of $5-$8 per endpoint monthly.
They counted many of the instances and licenses as duplicates despite them only being alive once, which was frustrating.
I did not notice a significant increase in cost after adding SentinelOne.
 

Valuable Features

Cortex XSOAR offers user-friendly automation, integration, and playbook creation with efficient remediation, security features, and AI-enhanced threat intelligence.
SentinelOne Singularity Complete offers robust security, automation, and integration, excelling in threat prevention and minimal disruption across platforms.
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Their support team walked us through configuring the agent to handle other third-party tools properly.
The security aspect is the most valuable feature for me.
 

Categories and Ranking

Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
46
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
SentinelOne Singularity Com...
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
192
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Anti-Malware Tools (2nd), Endpoint Detection and Response (EDR) (3rd), Extended Detection and Response (XDR) (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Palo Alto Networks Cortex XSOAR is designed for Security Orchestration Automation and Response (SOAR) and holds a mindshare of 11.2%, down 13.2% compared to last year.
SentinelOne Singularity Complete, on the other hand, focuses on Endpoint Detection and Response (EDR), holds 5.8% mindshare, down 9.0% since last year.
Security Orchestration Automation and Response (SOAR)
Endpoint Detection and Response (EDR)
 

Featured Reviews

NikhilSharma2 - PeerSpot reviewer
Ability to multiple playbooks to fetch data from multiple firewalls and utomated several tasks, including vulnerability scans and SOCL (Security Orchestration, Automation
Recently, they started implementing microservices in XSOAR, which has improved quality and addressed previous issues. However, they should focus more on licensing costs. The user licensing fees are quite high. For example, I received a quote for XSOAR, and it was $12,000 per user per year. If you have a SOC team of 30 members/analysts, you're looking at a substantial expense. They should consider reducing these costs since this high pricing seems to be more about profit. So, there is room for improvement in the pricing. Moreover, the reporting and dashboard features are decent but could be improved. The user interface (UI) is quite heavy and takes time to load, which is a major drawback.
Asim Naeem - PeerSpot reviewer
It integrates well with other platforms, is user-friendly, and is stable
SentinelOne Singularity Complete integrates with our other security solutions, correlating data from NDR, ADR, SIEM, and XDR tools. All this information is consolidated within SentinelOne, providing a centralized access point. SentinelOne Singularity Complete has helped us streamline our security operations by consolidating multiple solutions into a single platform. We are currently in the process of acquiring a threat intelligence platform to complete our security stack. We use Ranger to monitor our network and track connected devices. This is crucial because it helps us quickly identify unauthorized machines connected to our infrastructure, including personal devices. We have additional security measures in place, but Ranger provides an extra layer of protection. It also alerts us if the SentinelOne Singularity Complete agent is missing from any new or existing machines, allowing us to take appropriate action. SentinelOne Ranger's agentless and hardware-independent nature is crucial for our environment with 26,000 endpoints, as manual management of such a large number would be extremely challenging. Ranger uses a multi-layered approach to prevent vulnerable devices from being compromised. We employ scanners, network configurations, and a risk scanner to assess devices, endpoints, servers, and cloud infrastructures. Vulnerability reports and timelines for remediation are shared with device owners or custodians. This proactive strategy enables us to address vulnerabilities efficiently and secure our infrastructure. SentinelOne Singularity Complete has significantly enhanced our security posture. While no system is impenetrable, this solution has brought us closer to achieving a high level of protection, ensuring we maintain at least a 90 percent security level. Our team is dedicated to refining alerts and eliminating false positives from our solutions. Additionally, a team is responsible for identifying and excluding alerts from the solution. We can manually expedite this process by reviewing these elements and utilizing our security tools. We have been able to reduce the alert volume by 20 percent. Our 30-member Security Operations Center team has been able to redirect their focus to other tasks due to the time saved after implementing SentinelOne Singularity Complete. SentinelOne Singularity Complete has helped us improve our mean time to detect threats, which we accomplish using the Vigilance service for detection and response. SentinelOne Singularity Complete has helped us decrease our organizational risk. We utilize the Security Scorecard to manage our security posture, which has remained steady at 90 percent.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
832,138 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
12%
Government
10%
Manufacturing Company
9%
Computer Software Company
19%
Manufacturing Company
8%
Financial Services Firm
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Even though customers often comment on the price, the potential savings come from managing a large number of security events with a limited number of analysts. This leads to economic advantages des...
What needs improvement with Palo Alto Networks Cortex XSOAR?
The complexity of Cortex XSOAR has a trade-off with its versatility. The product can be tailored for each deployment to respond to specific customer needs, and this complexity may be seen as a down...
Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about SentinelOne?
The AI solution makes it easy for customers to detect and manage policies, as well as documents that help customers manage their platform.
 

Also Known As

Demisto Enterprise, Cortex XSOAR, Demisto
Sentinel Labs, SentinelOne Singularity
 

Overview

 

Sample Customers

Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about Microsoft, Palo Alto Networks, Splunk and others in Security Orchestration Automation and Response (SOAR). Updated: February 2025.
832,138 professionals have used our research since 2012.