No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Chief of IT Architecture at a financial services firm with 10,001+ employees
Real User
Top 5
Nov 27, 2025
Integrated detection and automation have transformed our security operations and provide comprehensive visibility across endpoints, network, and cloud
Pros and Cons
  • "Palo Alto is the core of the security infrastructure in the environment."
  • "However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution."

What is our primary use case?

Cortex XDR by Palo Alto Networks has been in use for more than two or three years, starting in 2022.

What is most valuable?

The most important features of Cortex XDR by Palo Alto Networks are the tight integration with the Palo Alto environment. It is not just an EDR solution, but a full security suite with automation as the main driver, as well as the networking side.

EDR solutions are generally lacking on the networking side as they focus solely on the endpoint side. The SOAR side is another valuable feature because it is being used extensively, particularly the Triage functionality and effective triage without human intervention.

In the future with new AI technologies, there is significant potential. A POC is currently being conducted with ARIS, the Palo Alto AI offering, and it is planned to be purchased for the next year.

When using Cortex XDR by Palo Alto Networks in a tightly populated environment, all vulnerabilities, threats, and zero-days that can affect the environment become visible, along with how to mitigate them in a fast way to detect and mitigate.

What needs improvement?

More integration and marketing would be beneficial. This is a full cloud solution, but there are some GRC-related issues that can be bypassed to some extent. In the future, there may be some issues in the environment because although the product receives telemetry and it works, it is actually getting much more information for analysis.

The preference would be to have separated isolated zones where if working in the Middle East, that data should reside in the Middle East, be analyzed and processed, and not be shared through other regions.

The ESA, customer success, and focus services are paid for, and these services can be utilized for other products as well, which is a huge advantage. However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is stable with no performance issues.

Buyer's Guide
Cortex XDR by Palo Alto Networks
October 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
915,341 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is scalable.

How are customer service and support?

A special agreement exists with Palo Alto for customer focus and customer success services, so it is not a problem.

Before that, when comparing with other vendors, if you do not have customer CS and PS services, there are two services, and PS as well. Three services have been purchased: customer success, focus services, and professional services.

If all three services are purchased, it is very straightforward. If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system. All three services are being paid for. From this perspective, if all three services are purchased and they come with the cost, it is superb. If any of these services are missed or if you do not get a chance to implement these services, it becomes a problem.

Which solution did I use previously and why did I switch?

As the IT Security landscape is changing in unprecedented level, Cortex XDR is being selected for major detection, mitigation with rapid Automation capabilities covered in this solution.

How was the initial setup?

In the initial phases, the setup of Cortex XDR by Palo Alto Networks was not straightforward because the product was new. There were some issues, but as the market increased, I can assure that if the project were done this year, it would be much faster and more convenient.

Three years ago, the integration and deployment were not very fast. There were some issues at that time. Now, if the project were started from scratch this year or next year, there would not be any problem.

Which other solutions did I evaluate?

From the correlation perspective, Cortex XDR by Palo Alto Networks is ahead of CrowdStrike.

What other advice do I have?

Cortex XDR by Palo Alto Networks has been used extensively. This organization is one of the largest Palo Alto companies in the region.

Palo Alto is the core of the security infrastructure in the environment. The products in use related to Palo Alto on the XDR side are mainly integrated with the EDR side, automation, and reporting. It is integrated with Palo Alto XSOAR, Prisma Cloud, Palo Alto firewalls, Prisma Access, and the client side. The cloud SOC side and XDR cloud are also being used. The only thing that has not been tested is the AI Cortex XDR AI agent. Other than this, all functionalities for the XDR side are being used. It is a combination of EDR and automation, as well as logging with Triage.

There is hands-on experience working with Cortex XDR by Palo Alto Networks.

Palo Alto is the main vendor driving the XDR market. It is not an EDR which solely relies on the endpoint agent. The difference is that integration and collection of other log sources and the detection and mitigation technologies are highly valued. It is possible to integrate firewalls, another vendor firewall. It is not just collecting logs, but also making meaning of that log or action compared to other devices.

It is working at the endpoint side, the networking side, the response side, the vulnerability side, as well as the governance side. It is much more sophisticated in terms of detection and mitigation compared to CrowdStrike. CrowdStrike is the main vendor in the market or the head-to-head vendor that can compare with Cortex XDR by Palo Alto Networks.

What is missing in the XDR side is the hype, as EDR started before XDR. As you know, EDR response came first, then XDR followed. CrowdStrike got all the benefits of being first, and then Palo Alto came after. From the customer side, CrowdStrike is much more used in the market, so it has received much more information and IOCs coming from the endpoint compared to Palo Alto. However, Palo Alto IOCs are mainly coming from not only the endpoint side but also from the networking side, cloud side, and any other telemetry mainly from the Palo Alto ecosystem.

CrowdStrike markets itself as the independent vendor which can integrate with major security vendors. You can integrate Palo Alto products with CrowdStrike, you can integrate InfoBlox with CrowdStrike, or you can integrate any product with CrowdStrike because it is an API-driven integration and publicly available in the market. On the XDR side, Palo Alto should make this integration available so that you can integrate it.

Triage can be performed more than two or three times much faster compared to classical triage. However, human intervention is still needed because the product is in English. Since the main language is not English, somebody from the SOC level two conducts additional triage for high and critical incidents.

The main point is related to Palo Alto because the ESA licensing approach is being used. Credits are being received for the Strata side, XDR side, and cloud side. The credit usage is very convenient, but this product is not cheap. Hefty money is being paid to work with and use this product compared to other solutions. In short, this is not a cheap solution.

It cannot be recommended to small companies. It is good for large companies who want the best solutions because Palo Alto offers the best of the best solutions and have the money to pay for it.

Regarding value, security value versus real monetary cost is an effective solution. However, when going into deep analysis, whether this product is needed and if it gives real value is uncertain. It is working fine, but it is not known if it is a deal breaker in terms of cost optimization and effectiveness. It is good.

First, if you have many products with Palo Alto on the networking side, SOAR side, cloud side, and cloud security, Cortex XDR by Palo Alto Networks is the right choice.

If you want an independent solution which is more rapid to deploy and agile, XDR may not be the right choice. Customers need to take into account their usage of the Palo Alto environment. If there is heavy Palo Alto usage, XDR is the right choice. If there is no Palo Alto in the environment, EDR instead of XDR is recommended.

This review gives Cortex XDR by Palo Alto Networks a rating of 8 out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Janardan Pavaskar - PeerSpot reviewer
SOC Manager at a tech vendor with 10,001+ employees
Real User
Top 5
Sep 18, 2026
Incident response has improved and investigation time is reduced with unified behavioral insights
Pros and Cons
  • "Since using Cortex XDR by Palo Alto Networks, our MTTR has reduced, which means the mean time to resolve any ticket has been reduced."
  • "I am facing issues with customer support for Cortex XDR by Palo Alto Networks, so I am not satisfied with customer support."

What is our primary use case?

We have created use cases for Cortex XDR by Palo Alto Networks depending on customer requests and infrastructure, so there were many use cases that we developed.

There was a request from a customer regarding non-personal accounts to be listed, which I handled using Cortex XDR by Palo Alto Networks.

There are multiple use cases when different users use different applications, and during that period, we implemented Cortex XDR by Palo Alto Networks according to those use cases.

What is most valuable?

Cortex XDR by Palo Alto Networks has multiple features, including forensics, host insight, event collection, and checking different features such as recording, data lake storage, behavior profiling, inventory, search and destroy.

Cortex XDR by Palo Alto Networks has positively impacted my organization by being very user-friendly, and whenever we integrate it, the integration is seamless and we receive quick responses.

Since using Cortex XDR by Palo Alto Networks, our MTTR has reduced, which means the mean time to resolve any ticket has been reduced.

I have seen almost a thirty to forty percent reduction in costs or time since using Cortex XDR by Palo Alto Networks for a month.

What needs improvement?

There are many ways Cortex XDR by Palo Alto Networks can be improved, especially since there are bugs in the product. When normalizing anything or when issues occur, we have to open a priority one or priority two ticket with Palo Alto, so it should accept and resolve it on priority.

Whenever product level support is needed for Cortex XDR by Palo Alto Networks, it should provide a response because a ticket that is raised should receive a response.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for five years.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is relatively stable, but there are some glitches.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks has huge scalability, and you can deploy it according to your requirements.

How are customer service and support?

I am facing issues with customer support for Cortex XDR by Palo Alto Networks, so I am not satisfied with customer support.

How was the initial setup?

It took my team almost one month or more to start seeing meaningful value from Cortex XDR by Palo Alto Networks after deployment.

What was our ROI?

I have seen a return on investment with Cortex XDR by Palo Alto Networks, as both money and time have been saved, which is a great solution.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Cortex XDR by Palo Alto Networks is that it is at a much higher rate.

What other advice do I have?

I would rate Cortex XDR by Palo Alto Networks at an eight out of ten because it is a good product, but the main problems are with support, such as ticket opening and response times, which reduce the overall rating. Beyond that, the product is good and it works.

Regarding Cortex XDR by Palo Alto Networks' AI capabilities, I think there is improvement on a day-by-day basis, and that is a positive thing.

The accuracy and reliability of Cortex XDR by Palo Alto Networks' AI output is good as of now, but there are many things that need improvement, especially regarding security and governance on AI, which depends on feedback whenever there is any breach, as we have opened a ticket with the support team and they are conducting data collection.

Cortex XDR by Palo Alto Networks is deployed in my organization mostly as a hybrid cloud.

From a security perspective for Cortex XDR by Palo Alto Networks, we faced challenges with accessibility and determining how data routing would go to Cortex, which required patience and architectural level understanding. This is something that takes time, but once it is done, you will be satisfied.

What ultimately convinced me to choose Cortex XDR by Palo Alto Networks over other solutions was that it had a more user-friendly GUI and was overall more friendly.

If I had to highlight one major outcome my organization achieved with Cortex XDR by Palo Alto Networks, it would be a reduction in incident response time, and it is more focused on the attack surface.

Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats by allowing us to see what is happening in the window, distinguishing between true positives and false positives through training, analysis, and AI, so we can take precise decisions to block and take necessary action on the end machine, whether it might be a firewall, web, or cloud.

Cortex XDR by Palo Alto Networks has helped me communicate security value or risk reduction to leadership and executives through a dashboard where I can project outcomes.

I recommend Cortex XDR by Palo Alto Networks for others looking into using it.

My overall review rating for Cortex XDR by Palo Alto Networks is eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 18, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
October 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: October 2026.
915,341 professionals have used our research since 2012.
Manager at a financial services firm with 10,001+ employees
Real User
Top 20
Jul 2, 2026
Endpoint monitoring has improved malware detection and drives focused vulnerability reviews
Pros and Cons
  • "Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats, as we are able to see the files, unwanted files, unsecured files, and unauthorized files, so we are quarantining them."
  • "I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."

What is our primary use case?

I use Cortex XDR by Palo Alto Networks in my company, which is a finance organization. Currently, more than 50,000 to 60,000 people are using Cortex XDR by Palo Alto Networks in my company. We do not have an administrator for Cortex XDR by Palo Alto Networks.

What is most valuable?

All features of Cortex XDR by Palo Alto Networks are good; the feature particularly important to me is malware detection, which is good.

Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats, as we are able to see the files, unwanted files, unsecured files, and unauthorized files, so we are quarantining them. Additionally, it is able to block USB access.

The major outcome my organization achieved with Cortex XDR by Palo Alto Networks is that we find malware files and identify vulnerabilities that attackers could exploit. We are able to highlight these findings and ask the team to review the process, identify which executable files are vulnerable, obtain CVE data, and identify the hosts that are vulnerable to published CVEs.

What needs improvement?

I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data. For example, we have servers as well as endpoints, but segregation is not available in some areas, such as device control violation.

Segregation in Cortex XDR by Palo Alto Networks means I want to select and filter only servers, but that filter is not available. When I want to write a query in some other areas, I am not able to identify where I want to filter very narrowly. I am unable to see filters for servers separately and for workstations separately.

I would like to see additional features in Cortex XDR by Palo Alto Networks such as a query builder, then a dashboard for device control violation, and I want a separate dashboard with queries as well.

I would also add that if the dashboard of Cortex XDR by Palo Alto Networks remains more user interactive, it will be much better. We have not created any dashboard and have only seen the predefined ones. Additional dashboards would be helpful, such as one for device connection lost, where we can see every hour's data from a single point.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks since September.

How are customer service and support?

I would rate their technical support for Cortex XDR by Palo Alto Networks as a nine.

Which solution did I use previously and why did I switch?

Before Cortex XDR by Palo Alto Networks, I did not work with other products.

How was the initial setup?

The initial setup of Cortex XDR by Palo Alto Networks did not present any difficulty; we did not face any kind of difficulty.

What about the implementation team?

I installed Cortex XDR by Palo Alto Networks with the help of a consultant. The implementation of Cortex XDR by Palo Alto Networks took approximately not very long; it was very easy.

Which other solutions did I evaluate?

Before choosing Cortex XDR by Palo Alto Networks, I did evaluate other options.

What other advice do I have?

Cortex XDR by Palo Alto Networks has helped me communicate security value or risk reduction to leadership or executives, as risk reduction is evident. We have not fine-tuned it yet, but we have just procured it as a new tool. However, we are able to see some of the cases which are genuine, and hopefully the results will be good.

The pricing for Cortex XDR by Palo Alto Networks is fine.

I bought Cortex XDR by Palo Alto Networks from a third party.

I would rate this product overall as a nine.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 2, 2026
Flag as inappropriate
PeerSpot user
reviewer2813907 - PeerSpot reviewer
Managed Detection And Response Delivery Analyst at a tech vendor with 10,001+ employees
Real User
Top 5
Apr 2, 2026
Advanced queries have improved threat investigations and deep malware analysis capabilities
Pros and Cons
  • "Once you become familiar with it, Cortex XDR by Palo Alto Networks is a more powerful tool and I would say that I prefer it over MDE because it is a stronger tool for me."
  • "Cortex XDR by Palo Alto Networks is a strong tool, but it is true that digesting information sometimes makes the tool go a little bit slower."

What is most valuable?

The best features of Cortex XDR by Palo Alto Networks are apparent when I compare it to other tools. Palo Alto is more difficult initially, but once you start learning how to use it, particularly the query language, you realize its power. When we use MDE, it uses KQL, which is similar to SQL. However, Cortex XDR by Palo Alto Networks uses XQL, which is more difficult but allows you to get significantly more information. Once you become familiar with it, it is a more powerful tool. For example, Cortex XDR by Palo Alto Networks has an automatic tool, which is a sandbox for local analysis that is incredibly useful for malware detection. I would say that I prefer Cortex XDR by Palo Alto Networks over MDE. To sum it up, it is a stronger tool for me.

The way we detect, investigate, or respond to threats with Cortex XDR by Palo Alto Networks is basically the same as with other tools, but once we start using Cortex XDR by Palo Alto Networks, we have different tools for different clients. When we use Palo Alto, it is basically the same, but we normally get a little bit more time because if we want to make a strong investigation for one incident, we have to make queries and look at different parts of the interface. There is a part of the interface called alert debug, which is more technical. If you click on the incident in alert debug, you can see the whole information of the incident in raw JSON format. To sum it up, it will make the investigation slower, but as I said before, it is better for the investigation because you have more information.

What needs improvement?

In Cortex XDR by Palo Alto Networks, there are areas that have room for improvement. I have been working with XQL, the language they are using, and they can really work on that language. The main difference between CrowdStrike, MDE, and Cortex XDR by Palo Alto Networks is that Cortex XDR by Palo Alto Networks is the most powerful tool, but XQL is a challenge. When I see colleagues who are not that experienced, they are looking for how to use XQL. They could either use another language to ingest the data sets, which is the main reason why they use XQL, or make XQL easier with tutorials. The difficult part for analysts is learning how to use Cortex XDR by Palo Alto Networks and how to look for information. However, once they know the language, the interface part is very easy. To sum it up, I would say either implement another language, which is not a real solution, or create tutorials to make it easier for analysts to learn XQL.

For how long have I used the solution?

I have used Cortex XDR by Palo Alto Networks for one year and a half.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is a strong tool, but it is true that digesting information sometimes makes the tool go a little bit slower. I would rate this as a seven.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is very scalable, but I do not think it is affordable for a small enterprise. For a small enterprise, MDE would be more appropriate, but that is another question. Regarding scalability, because of the data digesting, I do not really know how it will work for a small enterprise. I would rate this as an eight.

How are customer service and support?

The technical support for Cortex XDR by Palo Alto Networks is very good. Once I talked to technical support in a live chat, and it was helpful. I think it may have been AI, but it solved my question. I would rate this as a ten.

How was the initial setup?

Cortex XDR by Palo Alto Networks requires maintenance. However, not for me personally, because I am not the one doing the updates. I know that sometimes L2 and L3 teams from a SOC have to coordinate with the updates that the tool makes so they can use some parts of the interfaces. The point is that my team in L2 and L3 does not really have to do anything for the updates. The tool updates itself, and in the new patch, we are told what the new part is, but not from our part in the SOC. You do not have to do anything.

What other advice do I have?

It depends on the user and how serious you are going to take the learning path of the language with Cortex XDR by Palo Alto Networks. Taking into account all the different interfaces and a normal user starting with the tool in L1, I would say that to completely dominate the tool, if you want to reach proficiency level five, you can achieve this in one month. However, to completely dominate the tool, it can take four to six months because it depends on how many incidents you get to see. I do not know if a new user from another SOC gets to see all the incidents I see. However, in my SOC, I would say that in six or seven months, you can achieve mastery.

My overall rating for Cortex XDR by Palo Alto Networks is a ten. It is my favorite tool, along with CrowdStrike, and I would rate it as a ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Apr 2, 2026
Flag as inappropriate
PeerSpot user
Sunny-Kumar - PeerSpot reviewer
Cyber Security Analyst at airtel
Real User
Top 5
Dec 4, 2025
Automated incident workflows have reduced manual triage while reporting and playbooks still need refinement
Pros and Cons
  • "My advice for others looking into using Cortex is that it is very easy to use and very useful for the customer environment, whether it's a public or private one."

    What is our primary use case?

    I have used Cortex for more than I worked in Cortex. I have around 2.1 years of experience using Cortex XDR, but currently, I am using Cortex.

    My main use case for Cortex is to prepare the chart flow of the main Cortex XDR. In Cortex XDR, we have to alert for our auto-triaging and repetitive tasks, and we use it for triage automatically. We use it for CTI Cyber Threat Intelligence enrichment, such as IP, URL, and IOCs, automatically. It also has reputation checks using VirusTotal, abuse.ch, and others for the purpose of the uses in Cortex XDR. It also includes playbook automation. For example, Cortex has many playbooks for phishing, malware, infection, ransomware, and lateral movement. These playbooks automatically conduct the entire investigation and response. In case management, it stores details, timelines, evidence, and others for easier incident tracking. From the SOC perspective, we have to reduce false positive cases, and it reduces duplicate alerts, allowing our SOC analyst to respond faster. On the other hand, for the use of the EDR, Cortex provides detection behavior, attack prevention, and can always identify file-less and memory-based attacks and UEBA normally.

    An additional point I need to add in Cortex XDR is manual commands during the investigation, such as Cortex war room commands, IP reputation checks, hash look analysis, and endpoint isolation. These help us to conduct a faster investigation. Additionally, we need to create and modify playbooks according to the organization and the needs of the organization's use cases, for example, auto-disabling a user in case of a suspicious login, auto-quarantining an endpoint with malware, and an auto-phishing and investigation workflow. We use Cortex for reporting to generate incident summary reports, post-incident reviews, and RCA documentation. We integrate it with tools such as SIEM, EDR, firewall, email security, web, and others for alert correlation.

    What is most valuable?

    The best features of Cortex are automated incident response, playbook automation, cyber threat intelligence, and management. It includes case and incident management, such as incident details, evidence, timelines, and using the dashboard. There is a war room for investigation and to consume alert correlation rules to reduce noise and false positives. It has over 700 integrations. It works with SIEM, EDR, firewall, email security, the cloud environment, and many others. Additionally, it has endpoint detections, behavior analytic UEBA, and machine learning-based detection using ML modules to detect advanced threats. There's a centralized data lake and customized dashboard reports.

    I find automation through the playbook to be the most valuable feature I use day-to-day. Playbooks save analyst time. If used for Cortex, it saves the analyst's time with a reduction in false positives. For IOC enrichment, we utilize MTDR, mean time to respond, to resolve incidents faster.

    I notice a positive impact since using Cortex. We experience a faster, quicker response. Regarding positive changes, if we have a short positive, we investigate the IP, URL, VirusTotal, and abuse.ch. We use XDR, and it's fast and reliable with no human error. It automatically works to reduce the workload of the SOC analyst, thus decreasing manual work.

    What needs improvement?

    There are no other improvements Cortex needs in my opinion.

    For how long have I used the solution?

    I have around 2.1 years of experience using Cortex XDR, but currently, I am using Cortex.

    What do I think about the stability of the solution?

    Cortex is stable in my experience.

    What do I think about the scalability of the solution?

    Cortex has good scalability and can handle growth and increased workloads well.

    How are customer service and support?

    The customer support from Cortex is very good and very useful.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I did not use a different solution before.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that it is high, but it is better for the SOC environment and for the users.

    What was our ROI?

    I notice time saving as a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that it is high, but it is better for the SOC environment and for the users.

    Which other solutions did I evaluate?

    Before choosing Cortex, we looked at different platforms for automation and chose one after reviewing which one was performing higher in the market, apart from Cortex.

    What other advice do I have?

    My advice for others looking into using Cortex is that it is very easy to use and very useful for the customer environment, whether it's a public or private one. It is extremely helpful from a SOC perspective, requiring very little time to manage situations, especially during integration, which is necessary. Cortex is very useful and cost-effective, in addition to being very easy to use.

    My company has a business relationship with the Cortex vendor for business purposes.

    I would rate this product a 7 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    E Prkl - PeerSpot reviewer
    Service Desk and Security Engineer at Hipp
    Real User
    Top 10
    Aug 20, 2026
    Comprehensive host visibility has strengthened prevention and enabled rapid incident response
    Pros and Cons
    • "Cortex XDR by Palo Alto Networks has helped us a lot with securing the whole environment and the whole IT structure, giving us full knowledge of what is happening on the client and enabling us to take action right away from a single point for managing security operations on the hosts."
    • "In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."

    What is our primary use case?

    My main use case for Cortex XDR by Palo Alto Networks is to secure the agents and hosts, and I use Cortex portal for troubleshooting and explaining security incidents.

    It helps because it gives a lot of detailed information regarding the situation, what was happening, which processes were involved, and at which exact time it happened. This information helped us a lot to determine what really happened.

    I can give a specific example of how I use Cortex XDR by Palo Alto Networks in my daily work. We are getting a notification in our ticketing system from Cortex once the incident appears in Cortex system. Then I analyze the logs and all the information gathered by Cortex agent and I check all the processes which were involved. Then I consult with my colleagues, and after that, I consult with the user, trying to figure out why it happened.

    What is most valuable?

    The best features Cortex XDR by Palo Alto Networks offers are Live Sessions with the host. I can connect to the host directly through Cortex, block the host, cut off the network on the host, and manage the hashes from the processes. I can allow or block each and every process on the host or in the general ecosystem. Those are the best features.

    On a daily basis, I find myself using the allowing and blocking of hashes from certain services or processes the most, and those are the features I am using most frequently.

    Cortex XDR by Palo Alto Networks has helped us a lot with securing the whole environment and the whole IT structure. Since every computer has Cortex agent installed, now we have full knowledge of what is happening on the client, even on computers which are not managed by our MDM. This has helped us a lot to make the whole organization secure, and we can take action right away. Cortex is a single point for us when it comes to managing security operations on the hosts.

    I can share specific outcomes or improvements I have seen since deploying Cortex XDR by Palo Alto Networks. Once we implemented this tool, at the beginning we had a lot of incidents, almost all incidents were created by the users, due to a lack of awareness, knowledge, and security awareness from the user's perspective. After we had a lot of awareness campaigns about this tool and about proper behavior on the internet or in daily work, we reduced the number of incidents by up to 80 to 90 percent.

    What needs improvement?

    Cortex XDR by Palo Alto Networks can be improved.

    I would like to see easily manageable filters in Cortex XDR by Palo Alto Networks which can help us to reduce the noise from Cortex, meaning the false positives or not really important situations happening on the hosts. This might improve the use of Cortex platform.

    On a scale of 1 to 10, I would rate Cortex XDR by Palo Alto Networks an 8. I am really happy about using this tool and this platform. In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement. Maybe making the interface a bit more user-friendly would help. But I would say that is the only thing.

    For how long have I used the solution?

    I have been using Cortex XDR by Palo Alto Networks for over three years.

    What other advice do I have?

    I think Cortex XDR by Palo Alto Networks AI capabilities in terms of governance and security is a really good idea, and I believe it is going to help us a lot in terms of quickly solving incidents or finding some useful features on the platform itself.

    Regarding Cortex XDR by Palo Alto Networks AI capabilities for accuracy and reliability of output, I believe those kinds of tools are still in development mode or stage, so I believe it is going to be only better and better in the future.

    I believe the biggest security challenge we were facing before implementing Cortex XDR by Palo Alto Networks is just people's awareness in terms of security behavior. Before Cortex XDR, we did not have any tool which might be so active on the host itself, since Cortex is blocking actions on the clients right away, which previously did not happen. Now it is way easier to manage those situations, and since we have this tool, we can react right away. Almost all dangerous situations are blocked on the hosts, preventing issues in the whole infrastructure. The whole organization is more secure. With the security awareness campaigns, we are having less and less such situations and security incidents, which is good.

    I was not the one who chose Cortex XDR by Palo Alto Networks, the company was. I believe the main reason for choosing Cortex XDR by Palo Alto Networks was that the company is using the network devices and network hardware from Palo Alto. Almost all of our network infrastructure is built on those devices, making it a natural choice to use their tools.

    Since Cortex XDR by Palo Alto Networks and Cortex agents are really powerful tools in terms of prevention, blocking unwanted situations and incidents helps us a lot with taking action right away. If the incident was really dangerous, we can take action and block the client right away from the platform. We can then spend some time analyzing or contacting the users or someone responsible for this, but with the secure environment and protection for other devices in our environment. Overall, I rate Cortex XDR by Palo Alto Networks an 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
    Last updated: Aug 20, 2026
    Flag as inappropriate
    PeerSpot user
    Anniki Iskandar - PeerSpot reviewer
    Junior Security Analyst at ITSEC Asia
    Real User
    Top 5
    Apr 14, 2026
    Centralized protection has strengthened endpoint security and simplifies real-time threat response
    Pros and Cons
    • "I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities."
    • "Cortex XDR by Palo Alto Networks could improve its user interface, which is more complicated compared to competitors such as SentinelOne."

    What is our primary use case?

    Cortex XDR by Palo Alto Networks is used on the enterprise level to prevent malware or attacks from hackers trying to compromise the server or endpoints. It's installed on every device connected to the network to ensure security and protects users from accidentally downloading malicious content that could lead to breaches. The centralized console simplifies setting things up for a company, eliminating concerns about user management since users lack the authority to alter configurations.

    What is most valuable?

    The most valuable feature of Cortex XDR by Palo Alto Networks is real-time protection. It runs immediately when the computer is turned on due to a feature called anti-tamper, preventing hackers or malicious actors from deleting the antivirus. Cortex XDR by Palo Alto Networks is centralized within one console, simplifying company-wide management.

    It also has an auto-block feature, removing malicious content in real-time. This reduces resource needs, as issues can be managed directly from a single location, eliminating the need for a management team at each site. Communication with the local personnel can resolve issues efficiently. The product's ability to monitor multiple endpoints saves time and costs.

    What needs improvement?

    Cortex XDR by Palo Alto Networks could improve its user interface, which is more complicated compared to competitors such as SentinelOne. SentinelOne's minimalistic UI is easier to navigate, requiring less time to learn. Cortex XDR by Palo Alto Networks' technical terminology can be challenging for companies where IT personnel may not be specialized in cybersecurity.

    Adding more features could complicate things further, which could detract from its effectiveness. Companies investing only in Cortex XDR by Palo Alto Networks without utilizing the broader Palo Alto ecosystem might consider alternatives.

    For how long have I used the solution?

    I have been using Cortex XDR by Palo Alto Networks for almost two years, from my intern period until I received my contract with the company.

    What do I think about the stability of the solution?

    Cortex XDR by Palo Alto Networks performs well during daily operations. If there is a threat or significant activity at one location, it manages without issues. Even in terms of server reliability, I have not observed any downtime in my experience.

    What do I think about the scalability of the solution?

    Cortex XDR by Palo Alto Networks is quite flexible in scalability. If a company hires a new employee or adds new devices, they simply request new licenses. Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.

    How are customer service and support?

    I typically communicate with the technical support and customer service of Cortex XDR by Palo Alto Networks during implementation, especially for troubleshooting related to server issues since that is critical.

    In an instance where a server could not connect to the console, support was swift to respond. They escalated the issue for deeper investigation, resolving it within an hour.

    How was the initial setup?

    In deploying Cortex XDR by Palo Alto Networks, we first gather extensive information about the company's system and devices, including the number of devices, servers, computers, laptops, and any mobile phones used for work. Once we ascertain compatibility, we proceed with installations, providing documentation and suggestions for upgrading if necessary.

    Two methods are utilized: mature companies use endpoint management programs to push installations, while startups handle it manually. Verification of connectivity to the console follows installation, with troubleshooting completed for any issues.

    What about the implementation team?

    I face several challenges when installing Cortex XDR by Palo Alto Networks. One challenge is installation on local computers in manufacturing environments. This is resolved by using VM broker servers for internal communication. However, resistance from some employees who question the necessity of installations remains a hurdle.

    Which other solutions did I evaluate?

    If a company purchases only Cortex XDR by Palo Alto Networks, I might advise them to think twice. However, if they already have components of the Palo Alto ecosystem, such as a firewall or threat intelligence, I recommend choosing Cortex XDR by Palo Alto Networks because it will be more powerful in that case.

    What other advice do I have?

    I do not track my customers' preferences regarding the deployment of Cortex XDR by Palo Alto Networks, but most times, I advise them to use the cloud option. With on-premises deployments, they need both a passive and active server to ensure Cortex XDR by Palo Alto Networks' availability at all times. This can be costly due to resource and maintenance needs.

    I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities. This integration allows log data from the firewall to be ingested and communicated with Cortex XDR by Palo Alto Networks, creating a more cohesive security strategy. They've already made significant improvements, so I believe it's adequate for now. I rate this product a 9.5 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    Last updated: Apr 14, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2338575 - PeerSpot reviewer
    Deputy Manager Data Centre at a financial services firm with 1,001-5,000 employees
    Real User
    Top 10
    Jul 26, 2026
    Behavior-based detection has transformed how we stop zero-day attacks and protect low-spec endpoints
    Pros and Cons
    • "Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
    • "On the pricing aspect, Cortex XDR by Palo Alto Networks needs to have a more reasonable rate, particularly for customers in Sri Lanka and Asian countries."

    What is our primary use case?

    Cortex XDR by Palo Alto Networks is used for detecting some legitimate traffic, especially when users concurrently try to log in from various locations through their VPN. When that occurs, users are informed and assisted in correcting the login issues. After resolving the situation, most of the VPN users are able to log in without issue. Cortex XDR by Palo Alto Networks also indicates potential unknown traffic to the SOC.

    Currently, a cloud deployment model for Cortex XDR by Palo Alto Networks is used. This model was installed before joining the team.

    What is most valuable?

    What I like about Cortex XDR by Palo Alto Networks is that it can understand zero-day attacks, which is a critical feature. It is behavior-based rather than signature-based, making it a very interesting and significant aspect in my experience.

    Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats by providing very fast responses. Having experience with both Kaspersky and SentinelOne, I find that it immediately responds to unknown traffic and unknown behaviors, which is vital for any environment, especially in the financial sector.

    Cortex XDR by Palo Alto Networks is particularly useful for blocking unknown attacks and can also disable USB and other peripheral devices, which is a significant advantage. This capability allows stopping unknown behaviors both at the user level and externally.

    A major achievement with Cortex XDR by Palo Alto Networks is its ability to recognize zero-day attacks, enabling it to understand and detect new and unknown attacks easily. This feature is crucial for any security environment.

    What needs improvement?

    In terms of improvement, Cortex XDR by Palo Alto Networks could enhance user-level capabilities before installation, particularly in properly preventing unknown peripheral devices from being plugged in. It also needs to better address third-party VPN client usage, which can sometimes create monitoring issues.

    Looking to the future, I would like Cortex XDR by Palo Alto Networks to improve its understanding of third-party VPNs and the ability to manage users logging in from multiple locations simultaneously. This is an area where enhancements could be beneficial.

    For how long have I used the solution?

    I have been working with Cortex XDR by Palo Alto Networks since 2016, and I have two years of experience with the SOC in Sri Lankan Airlines through KBSL Sri Lanka.

    What do I think about the stability of the solution?

    So far, I have not experienced any stability or performance issues with Cortex XDR by Palo Alto Networks; it is functioning smoothly in the current environment.

    What do I think about the scalability of the solution?

    Cortex XDR by Palo Alto Networks is scalable.

    How are customer service and support?

    Normally, tickets for support are generated through the distributor, and I have not directly communicated with the Palo Alto support team. In my past vendor role, direct communication with the distributor who managed technical support internally was maintained.

    The partner used for communication with Palo Alto Networks in Sri Lanka is Conex Private Limited, which is the exclusive distributor for Palo Alto.

    Which solution did I use previously and why did I switch?

    I personally have no experience with the security challenges before implementing Cortex XDR by Palo Alto Networks, as it was already installed before joining. However, I have experience with SentinelOne, which requires more RAM space for a single end-user compared to Cortex XDR by Palo Alto Networks, making it more valuable for customers. Many end-users cannot change their endpoints due to additional costs, but Cortex XDR by Palo Alto Networks is important for low RAM and utilization compared to other XDR products.

    When comparing Cortex XDR by Palo Alto Networks to other XDR products such as SentinelOne, the key differences include price and lower utilization from endpoints. Other products, such as Kaspersky and SentinelOne, tend to use more resources from end-user devices, which is a noteworthy distinction.

    How was the initial setup?

    The initial setup for Cortex XDR by Palo Alto Networks is not challenging, as I have experienced many endpoint devices and found the installation process straightforward within the environment.

    What about the implementation team?

    Cortex XDR by Palo Alto Networks was purchased from a local distributor, as it is often challenging to buy directly or through marketplaces without distributor support, which simplifies ticketing and other processes.

    What's my experience with pricing, setup cost, and licensing?

    On the pricing aspect, Cortex XDR by Palo Alto Networks needs to have a more reasonable rate, particularly for customers in Sri Lanka and Asian countries. This is crucial, as customers often depend on costs; despite its technical advantages, pricing is a significant factor in decision-making.

    What other advice do I have?

    What ultimately convinced me to choose Cortex XDR by Palo Alto Networks over other solutions is its low utilization, which is a major factor for my environment.

    Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices. Some other products do not meet these efficiency standards.

    From my knowledge, it is a very expensive solution, but it is good for a SOC. I would rate Cortex XDR by Palo Alto Networks a nine out of ten as a product and solution.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 26, 2026
    Flag as inappropriate
    PeerSpot user
    MahmoudOsama Abdo - PeerSpot reviewer
    Detection and Response Consultant at Inovasys
    Consultant
    Top 20
    Nov 11, 2025
    Has improved threat hunting efficiency and enabled rapid response to advanced attacks
    Pros and Cons
    • "The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."

      What is our primary use case?

      I am currently using SIEM solutions such as Sentinel and Microsoft Defender, ELK, and Wazuh as SIEM solutions, and Microsoft Defender as the EDR solution or XDR solution. I am working on VelociRaptor as the threat hunting and incident response component, and I am also working on Cortex XDR by Palo Alto Networks as the EDR component and XDR component.

      I have been using Cortex XDR by Palo Alto Networks for one year at Inovasys.

      Our customer uses Cortex XDR by Palo Alto Networks as an on-premises version.

      I am not working on the deployment of Cortex XDR by Palo Alto Networks that is related to our customer, but we can use it to investigate the generated alerts from the solution, not the implementation of the box.

      What is most valuable?

      The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response. This makes it a very good solution, similar to Microsoft Defender XDR.

      Cortex XDR by Palo Alto Networks is very effective for the default rules in blocking sophisticated threats in real-time. However, we cannot take any action related to the block agent for the custom rules. The default rule can take any action, but the custom rule does not take any action, making it very good for handling real attacks.

      Cortex XDR by Palo Alto Networks has a very good impact on preventing advanced attacks such as ransomware, which is very impactful malware for customers. It can take action by isolating a machine if any bad behavior is detected on the compromised machine, making it a very good solution for detecting attacks and protecting our customers from business continuity issues or bad reputation.

      The use of Cortex XDR by Palo Alto Networks has made it easy for analysts, as it does not create any workload for them, allowing them to work faster.

      What needs improvement?

      I do not see any weak points in Cortex XDR by Palo Alto Networks at this time. Every solution must have a weak point, and I have not seen a weak point until now.

      For how long have I used the solution?

      I have been using Arbor DDoS as a DDoS mitigation system for protecting our organization and our customer from DDoS attacks generated by threat actors for two years. It consists of three components like the TMS, the collector, and the leader that can control the alerts, view the alerts, and generate the templates. Arbor can be used to mitigate our DDoS attacks.

      What do I think about the stability of the solution?

      I think Cortex XDR by Palo Alto Networks is very stable, and I would rate it a 10.

      What do I think about the scalability of the solution?

      Overall, I rate the scalability of Cortex XDR by Palo Alto Networks as 10.

      How are customer service and support?

      If we face any problem while investigating with Cortex XDR by Palo Alto Networks, we can call the customer to open a ticket with the product vendors, and we can open a ticket with the vendor to resolve this issue, which is not related to the investigation team or analyst team.

      The support of Palo Alto Networks is not related to analysts. When we raise any issue, the support joins us quickly for resolving this error or issue. In my opinion, an eight is a very good scale for this product for technical support.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The alerting time with Cortex XDR by Palo Alto Networks is related to the rules. If a rule works in real-time, it generates a fast alert. If the rule operates on schedule, it generates the alert based on the detected incidents during the scheduled region. This depends on the rule, but the rule working in real-time provides fast response for alert generation.

      What about the implementation team?

      The dashboard of Cortex XDR by Palo Alto Networks is customized by us, and we can create the dashboard and the reports by the engineering team for Inovasys, which is related to the engineering team.

      The deployment and installation of Cortex XDR by Palo Alto Networks is handled by the engineering and customer teams, not related to my role as an analyst, since I focus on threat detection and response and not on implementing the agent.

      What was our ROI?

      Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.

      I see financial benefits after implementing Cortex XDR by Palo Alto Networks, as it is very cheap compared to Microsoft Defender XDR, saving or reducing costs by more than Defender.

      What's my experience with pricing, setup cost, and licensing?

      I think the pricing for Cortex XDR by Palo Alto Networks is very good, especially compared to Microsoft Defender, which is very expensive, and I would rate it an eight.

      Which other solutions did I evaluate?

      Cortex XDR by Palo Alto Networks' AI-driven endpoint security is very effective in detecting any unsuspicious or any un-behavior solution on the endpoint, and I would rate its effectiveness an 8 from 10.

      Cortex XDR by Palo Alto Networks' AI-driven endpoint security is very good at detecting unsuspicious behaviors.

      What other advice do I have?

      Regarding tuning alerts, we can tune the alerts that generate false positive alerts to more than 10 alerts per 30 days.

      The security analysts' workload has no significant increase with Cortex XDR by Palo Alto Networks.

      I would rate Cortex XDR by Palo Alto Networks a 9 from 1 to 10.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      PeerSpot user
      HectorRios - PeerSpot reviewer
      IT COMMUNICATIONS AND NETWORKS at Américas BPS
      Real User
      Top 5
      Oct 2, 2025
      Has detected high-risk threats effectively and provides strong behavioral protection
      Pros and Cons
      • "The normal protection was really effective, and we detected situations that if we didn't have Cortex XDR by Palo Alto Networks, it's highly likely that we would have been affected, but it protected the infrastructure."
      • "To jump from the partner to Palo Alto directly was challenging."

      What is our primary use case?

      We used Cortex XDR by Palo Alto Networks as our XDR solution. We had playbooks on the Cortex Data Lake on the Cortex management console where we configured conditions that start some compromises to protect access to servers, desktops, and laptops.

      The solution that we had was Cortex XDR by Palo Alto Networks installed in our infrastructure. We did not use the Cortex Cloud feature, just the XDR that we have on the infrastructure.

      How has it helped my organization?

      The normal protection was really effective, and we detected situations that if we didn't have Cortex XDR by Palo Alto Networks, it's highly likely that we would have been affected, but it protected the infrastructure.

      We designed playbooks that were automated by the console and in the management console, protecting and reacting to situations or issues. The way to automate the movement of the situation is using playbooks. They were detecting and responding to any high-risk threats.

      What is most valuable?

      The best features include the security level, which was nice. The Cortex Data Lake is nice too; it's really big. The way the cases used to collect the data is not intrusive, permitting the infrastructure to collect the data and send it to the Data Lake without problems.

      It is not intrusive.

      What needs improvement?

      I think there are areas that they can continue to improve and additional features that would be nice.

      For how long have I used the solution?

      I used Cortex XDR by Palo Alto Networks within the last year.

      What do I think about the stability of the solution?

      During the last four years, I can't remember having an important issue. We had issues, but nothing really important or big enough to say something was out of control. All the situations and issues were controlled in a good way by Cortex XDR by Palo Alto Networks.

      How are customer service and support?

      They did well with handling high-risk threats. I would rate Palo Alto support an eight or nine.

      I would give them an eight because in the majority of cases, we talk with local partners, and only in case of an emergency or a difficult issue, we jump to Palo Alto support. When we had that experience with Palo Alto support, it was nice service, but it was really difficult to get it. To jump from the partner to Palo Alto directly was challenging. I understand that it's part of the service, as the local partner just jumps up to Palo Alto support in case they need it. In some cases, when we faced an important issue, it was preferred to jump directly to Palo Alto to save time.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The setup was really easy to use and implement.

      What about the implementation team?

      They implemented it with a partner in Europe.

      Which other solutions did I evaluate?

      The main differences are that the service with CrowdStrike is difficult to manage, but the solution is really good too. The main difference is that Cortex XDR by Palo Alto Networks works with Unit 42, which is a significant advantage over CrowdStrike. CrowdStrike has its own team, but Unit 42 has a better reputation in that case.

      What other advice do I have?

      I have experience with SD-WAN solutions, but that conversation was in the past because I changed companies. When I wrote, I was writing from Konecta, but now I'm working for Americas BPS.

      We did not have Cortex Cloud as a solution. We have Cortex XDR by Palo Alto Networks. The solution's management was in the cloud, but regarding the management of the Data Lake and the runtime that Cortex used in the cloud to manage the agents, we had that. Cortex had another solution that is Cortex on the Cloud to protect solutions on cloud, but we did not use that solution.

      I think Cortex XDR by Palo Alto Networks is a really good tool and product. It works as Palo Alto said, and the solution keeps improving with all people in Palo Alto, including Unit 42, which is the unit that Palo Alto uses to detect and prevent issues. They work for Cortex, making it a really good product that is nice and easy to use.

      On a scale from one to ten, I rate this solution a ten.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
      Updated: October 2026
      Buyer's Guide
      Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.