Our primary use case is anti-malware and anti-exploit.
Security Engineer at U.S. Acute Care Solutions
We've had a significant increase in blocking with a decrease in false positives
Pros and Cons
- "We've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for."
- "The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
- "They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else."
What is our primary use case?
How has it helped my organization?
Traditional anti-virus is signature-based, whereas Traps is behavior-based. Therefore, it doesn't necessarily whitelist things, it looks for anything with bad behavior. Thus, we've had a significant increase in blocking with a decrease in false positives, because it's looking at how the files work, not just a list of files that it's been told to look for.
What is most valuable?
The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past.
What needs improvement?
Going from version 4 to version 5, they had a major change in their user interface. Version 5 is now all cloud managed, while it has a very intuitive, useful interface, it doesn't have all the features that were in the version 4 interface. For example, we lost being able to automatically trigger upgrades, like creating manual groups to upgrade with. It doesn't currently have the ability to use the Active Directory to create groups.
Buyer's Guide
Cortex XDR by Palo Alto Networks
December 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It's fairly stable. They do have bugs which come up every once in a while, but they're usually good about getting them taken care of within a release.
What do I think about the scalability of the solution?
It is definitely scalable.
Primarily, it is just being used by myself. The help desk also uses it. There are probably a total of around ten users.
We've deployed it to about 1500 endpoints so far. There is a possibility that we may expand our usage, but not in the foreseeable future. We are at pretty much at 100 percent deployment at this point.
How are customer service and support?
I would describe Palo Alto's technical support as audio waterboarding. They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else.
Which solution did I use previously and why did I switch?
We were previously using Sophos for antivirus, and are still using Sophos for antivirus, but we're using Traps to augment it.
How was the initial setup?
The initial setup was pretty straightforward on version 4, but on version 5, it is almost idiot-proof.
The initial deployment of getting the servers and everything up took about a week, but getting everything deployed was somewhere closer to six weeks.
What about the implementation team?
We implemented it in-house. We incrementally did some systems to make sure that it wouldn't block anything that it shouldn't. After that, we used Active Directory to push it to everything else.
Very little staff is required for deployment and maintenance, as Traps is self-maintaining.
What was our ROI?
I feel that we have seen ROI. There have been a number of blocked, bad files that could have gotten through, but were stopped by Traps.
What's my experience with pricing, setup cost, and licensing?
The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic. So, if you have 1100 computers today, you can license that. Therefore, as long as you're below your licensing cap, you're fine.
Which other solutions did I evaluate?
We looked at Palo Alto vs Sophos, which has a anti-malware system called Intercept X, but it did quite literally nothing. We thought about Symantec, but we didn't end up testing them against Traps.
What other advice do I have?
The implementation is fairly straightforward and easy. With version 5, everything is now on the cloud. It is easy to work with and use. I would use mobile device management (MDM) or Active Directory (AD) to push the file everywhere when installing it, as it will auto go from there. The management is pretty low. Thus, it will be set it, and for the most part, you can forget it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Specialist at RateGain
Scans for unwanted and malicious activity on endpoints and servers, creating alerts and incidents
Pros and Cons
- "The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
- "There's room for improvement with Mac device installations, which can be challenging."
What is our primary use case?
We use Cortex XDR by Palo Alto Networks for endpoint security. It scans for unwanted and malicious activity on endpoints and servers, creating alerts and incidents.
What is most valuable?
The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security.
What needs improvement?
There's room for improvement with Mac device installations, which can be challenging.
For how long have I used the solution?
I have been using the tool for two years.
What do I think about the scalability of the solution?
About 20 people in our company use Cortex XDR by Palo Alto Networks across the country.
How was the initial setup?
We've had some issues isolating endpoints and have sought support from Palo Alto for that.
What's my experience with pricing, setup cost, and licensing?
The cost depends on your chosen license type, like Pro or other licenses.
What other advice do I have?
I'd recommend using Cortex XDR by Palo Alto Networks for security purposes. It's good at detecting malware and is a better strategy than other antivirus solutions. I rate the overall solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Sep 1, 2024
Flag as inappropriateBuyer's Guide
Cortex XDR by Palo Alto Networks
December 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Owner and Executive Director at Cloud 9 s.r.o.
Good features, strong protection, and very scalable and stable
Pros and Cons
- "Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
- "It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
What is our primary use case?
It's mainly for protection against malware. We work very closely with a major partner of Palo Alto in the Czech Republic, and we have experience with the whole XDR solution. It's very useful for us and a very capable solution.
How has it helped my organization?
Clients have a big problem with phishing campaigns and phishing attacks. Cortex XDR provides some level of protection against malware spreading in the network with a wrong click of users.
What is most valuable?
Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection.
What needs improvement?
Its price is too high. That's a big problem for customers.
It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system.
In terms of additional features, there is very strong development. I have seen the roadmap, and we will see what happens. The roadmap looks nice, but it's still more of a network security solution than a content-security solution. The development in network security is quite strong. I'm very happy with that, but if a customer would like to implement a zero-trust security concept, it's necessary to combine this solution with other vendors. There is some part of the integration that is not so easy because you have to integrate rules and some features. It's not so automatic in network communication. You have to make some appropriate automation there, or you have to do it manually. It's time-consuming and it's also expensive.
For how long have I used the solution?
I have been using it from the beginning. It has been more than six years.
What do I think about the stability of the solution?
It's a very stable solution. I would rate it a nine out of ten in terms of stability.
What do I think about the scalability of the solution?
It's a very scalable solution. If you compare it with a SIEM solution from Palo Alto, it's very powerful. I would rate it a nine out of ten in terms of scalability. It's definitely for enterprises.
How are customer service and support?
Their technical support is not bad, but sometimes, when we have some issues, the support teams from Europe or Central Europe are not able to help us. We have to escalate the issue somewhere else, such as to the US. They have a very strong support team there, but it's time-consuming. Sometimes, it takes them days or weeks to solve some tricky problems, but their support for standard issues is okay. There is a very good response, but for a technical issue, it's sometimes more difficult. I would rate their support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I also worked a little bit with SentinelOne. Cortex XDR is very similar to the SentinelOne solution from the features point of view. It's a little bit different technology, but both solutions are very capable.
How was the initial setup?
It's somewhere in the middle. It's not for beginners, but if you know what to do, it's quite easy.
It's a cloud-based solution, which sometimes is an issue for customers. In the past, it was on-prem, but Palo Alto decided to change the policy and everything is cloud-based or located in the cloud. It's not a security problem from my point of view, but a few customers feel uncomfortable with sending data to the cloud and back.
What about the implementation team?
Very often, it's an in-house implementation.
What's my experience with pricing, setup cost, and licensing?
It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing.
What other advice do I have?
Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Project Manager at Incedo Inc.
A stable part of our security solution that correlates logs from relevant sources
Pros and Cons
- "The most valuable for us is the correlation feature."
- "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
What is our primary use case?
We use Cortex XDR as part of our security solution.
How has it helped my organization?
its a very good solution and single solution for entire infrastructure, give us good co-relation of incident. Single solution for Network, Endpoint, Servers.
What is most valuable?
The most valuable for us is the correlation feature. You are able to correlate data that is coming from the firewall, network, server, and endpoints. This is one of our main requirements and makes for a good product.
It works with the data lake in an agent-based or agentless manner.
It is easy to integrate most with network devices, including firewalls, and Active Directory. We use firewalls from different vendors including Palo Alto and Check Point, and it supports them.
What needs improvement?
There are some third-party solutions that are difficult to integrate with, which is something that can be improved.
What do I think about the stability of the solution?
We have not experienced any issues with respect to stability at this point.
What do I think about the scalability of the solution?
Scalability has not been a problem.
How are customer service and support?
We have been in contact with technical support and are satisfied with them.
How would you rate customer service and support?
Positive
How was the initial setup?
its a Straightforward
What about the implementation team?
We have an in-house team for deployment and maintenance.
What was our ROI?
It replace multiple solution and due to this it will reduce the Administrative effort.
Which other solutions did I evaluate?
I have run a PoC with both CrowdStrike and Cortex XDR, and from my observation, I felt that Cortex was much better at meeting our requirements. It is also easier to use.
CrowdStrike was difficult when it came to integrating with other products and it does not work on mobile devices.
What other advice do I have?
My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features. From my experience, it is one of the better ones in the market. That said, no product is 100%.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Network Engineer at a construction company with 10,001+ employees
Low system resource usage, reliable, and flexible
Pros and Cons
- "The most valuable feature of Cortex XDR by Palo Alto Networks is the low consumption of system resources. The solution uses a lot of AI and machine learning."
- "Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it."
What is our primary use case?
We are using Cortex XDR by Palo Alto Networks for all of our remote users because they are not connected to our on-premise data center.
What is most valuable?
The most valuable feature of Cortex XDR by Palo Alto Networks is the low consumption of system resources. The solution uses a lot of AI and machine learning.
What needs improvement?
Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately two years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is stable.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is scalable. add license and add many clients.
We have approximately 300 users using this solution in my company.
How are customer service and support?
I have not had an issue to need the support.
Which solution did I use previously and why did I switch?
We have previously used antivirus solutions. We decided to use Cortex XDR by Palo Alto Networks because of its flexibility.
How was the initial setup?
The initial setup of Cortex XDR by Palo Alto Networks is straightforward because it is in the cloud. The whole deployment took approximately one day.
I rate the setup of Cortex XDR by Palo Alto Networks a four out of five.
What about the implementation team?
We used the vendor to do the implementation of the solution.
What other advice do I have?
After the deployment of this solution, there is no need for maintenance.
I recommend this solution to others because it is easy to manage, reliable, and overall good to use.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Associate at HTH Global Network
Great threat detection capabilities and good internal threat intelligence
Pros and Cons
- "Has great threat detection capabilities."
- "The encryption is not up to the mark."
What is our primary use case?
This solution is a next-generation antivirus with more advanced capability and security. We have a partnership with Palo Alto.
What is most valuable?
Cortex XDR is very easy to deploy and has great threat detection capabilities and good internal threat intelligence.
It uses advanced AI analytics, behavior analytics, and custom-made detection to detect advanced threats before they occur.
If a customer says it's expensive- let's say I will say no it is not. Other values are added then it is more reasonable having strong features.
With a click, I can access the system and isolate it from other networks, and then go into a further forensic investigation of the current threat without compromising anything else.
Its stitches with external logs are perfect and enhanced.
What needs improvement?
1. Disk Encryption capability.
2. User group-wise admin role. They have module-wise roles but a user group-wise role is not available.
For how long have I used the solution?
We've been supplying this solution to customers for two years.
What do I think about the stability of the solution?
I have found this solution as NG AV is most stable compare with other solution
What do I think about the scalability of the solution?
The scalability is perfect.
How was the initial setup?
The initial setup is very easy.
What about the implementation team?
We implemented the solution with a vendor team, HTH Global Network. Their expertise is an eight out of ten.
What other advice do I have?
I recommend this solution, it works well and I rate it a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Servicio Posventa at a security firm with 11-50 employees
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
- "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
- "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
What is our primary use case?
Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.
What is most valuable?
One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers.
Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.
What needs improvement?
I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.
For how long have I used the solution?
I have worked with Cortex XDR by Palo Alto Network for about four years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.
On a scale from one to ten, I would give stability a nine.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Network is a scalable solution.
How are customer service and support?
Technical support is okay.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.
On a scale from one to ten, I would give the initial setup a seven.
What's my experience with pricing, setup cost, and licensing?
I don't like that they have different types of licenses.
On a scale from one to nine, I would give licensing costs a seven.
What other advice do I have?
I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback.
On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Technology Consultant at Trillennium (Pvt) Ltd
Excellent technical support, straightforward implementation, and cutting-edge technology
Pros and Cons
- "When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
- "In general, the price could be more competitive."
What is our primary use case?
We are not using it for our purposes because we are a Palo Alto partner. We propose it for our customers based on their requirements.
We are both a service provider and a reseller.
When the pandemic first began, the use cases were mostly for remote users. We deployed this for the majority of remote users.
What is most valuable?
When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud. We have a lot of advantages as a result.
It's a very simple implementation, and I have direct Palo Alto implementation available as well. So it's very simple. We haven't found any issues, so far the implementation is going well, I don't see any gaps.
What needs improvement?
In general, the price could be more competitive.
For how long have I used the solution?
In Palo Alto, we also work with all product lines, including Prisma and other product lines as required. Is a mix, it's a subproduct, we work with the mix of products.
We have been working with Cortex XDR by Palo Alto Networks for two to three years.
We get updates from Palo Alto directly.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is a stable product.
What do I think about the scalability of the solution?
It's a scalable solution, we have not had any challenges with the scalability of Cortex XDR by Palo Alto Networks.
Our customers range from medium to large enterprise companies. The adoption rate in small businesses is much less, but the majority of our requirements come from mid-to enterprise-sized businesses.
How are customer service and support?
Technical support is the best in class, in my opinion, because they have invested heavily in research and development. In terms of comparison and today's challenges, such as security and layers, Palo Alto complies with all of the challenges.
Which solution did I use previously and why did I switch?
In terms of Security, we are working with a few products and a few brands.
We use Palo Alto and we also work with Barracuda. These solutions are used on the web firewall and for email protection.
We work with the entire Barracuda product line, but specifically for email protection and web filtering.
Barracuda Essentials is included with O365 protections, we work with those solutions.
Palo Alto is part of a different vertical layer than Barracuda. It's distinct. They are very different.
How was the initial setup?
The initial setup depends on the environment, but as a technology, I would say it's simple. It's not that difficult.
The length of time it takes for deployment is determined by the project and the surrounding environment. We can only determine the timeframe based on that, pinpointing a specific time period is difficult.
It does not require maintenance because regular updates and monitoring are required. So if there is anything, new patches and the like, it is done automatically, and there is no additional implementation unless there are any infrastructure changes.
What's my experience with pricing, setup cost, and licensing?
In comparison to other competing products, it is based on the customer's needs and the environment. However, when compared to other products, the price is slightly higher, but when considering technology and new innovation, that is the plus I would say when it comes to being XDR.
The price could be more competitive because it is not on the price wall when you go and question Palo Alto XDR. It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable.
What other advice do I have?
So far, it has met all of our requirements, and it should be able to cater to a wide range of product lines.
We must first determine what their business requirements are, as well as what other technical layers we are considering, and then propose the appropriate sizing and solution.
We mostly promote Palo Alto, but it depends on the customer's needs, as well as their budget, infrastructure, and what their business requires, all of those factors come into play when recommending a solution.
When you compare it with other products, I would rate Cortex XDR by Palo Alto Networks a nine out of ten.
It's close to being rated a ten out of ten because of their level of support, and the other is the solution and the most recent technology.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
VMware Carbon Black Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?