Cortex XDR is used for monitoring and securing large numbers of endpoints, typically in the range of 5,000 to 10,000. It is considered to be an effective solution for mitigating security risks in these environments.
Site administrator officer at a tech services company with 11-50 employees
Effective machine learning capabilities, responsive support, and easy to understand
Pros and Cons
- "The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
- "Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
What is our primary use case?
What is most valuable?
The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions.
What needs improvement?
Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately four months.
Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
I rate the stability of Cortex XDR by Palo Alto Networks an eight out of ten.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is a highly scalable solution.
I rate the scalability of Cortex XDR by Palo Alto Networks an eight out of ten.
How are customer service and support?
The support team at Cortex XDR by Palo Alto Networks is very responsive and helpful in addressing any issues or challenges that may arise. They are highly accessible and knowledgeable about the products they offer. Overall, I have been very satisfied with the support provided by Palo Alto while deploying their solutions.
Which solution did I use previously and why did I switch?
We previously used CrowdStrike Falcon X.
Cortex XDR by Palo Alto Networks is easier to understand and use compared to CrowdStrike Falcon X endpoint. The dashboard and interface of CrowdStrike Falcon X can be cluttered, making it difficult for some users to understand where to begin when it comes to incident response or threat hunting. In contrast, Cortex XDR by Palo Alto Networks is simple to navigate and understand.
How was the initial setup?
The initial setup of the solution can take approximately one hour. One hour is the longest it has ever taken us for the setup. We have not had an issue with the setup.
I rate the initial setup of Cortex XDR by Palo Alto Networks a seven out of ten.
What about the implementation team?
We do the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help.
Customers tend to rather have a less expensive solution than the best one.
I rate the price of Cortex XDR by Palo Alto Networks an eight out of ten.
What other advice do I have?
We are using two engineers for the maintenance of the solution.
In our market here in Malaysia, the solution is perceived as being of high quality and providing good service.
I would recommend this solution to others, it is a good solution. It is my job to recommend solutions.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
The solution is not perfect and that is why I gave the rating of eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
IT Security Administrator at a tech services company with 1-10 employees
Provides more visibility than expected and lets us know if anything unusual happens on our network
Pros and Cons
- "Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
- "They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
What is our primary use case?
We have Cortex XDR on our endpoints, and we have managed threat hunting. We are using it for everything related to security. If we have a device we believe is compromised, we can do a scan of the device to check for malware. We look for indicators of compromise in our network. We also look for behavioral things, such as if people are, for some reason, sending a bunch of information out. We also monitor USB file copies to make sure sensitive data isn't leaving our systems. It is also for any kind of denial of service attack.
We are using its latest version. It is deployed on-prem. We have agent software on all our endpoints, and then we have on-prem devices managed through Panorama.
How has it helped my organization?
It has quite a bit of functionality. So, if anything weird happens on our network, Cortex normally lets us know.
What is most valuable?
Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful.
What needs improvement?
They've been having some issues with updating their endpoint agents, and it has been quite frustrating.
For how long have I used the solution?
I have been using this solution for about a year.
What do I think about the stability of the solution?
It's incredibly stable. It's Palo Alto; it's top of the line.
What do I think about the scalability of the solution?
It's enterprise-grade. They cover everybody from the federal government to large corporations. We're probably a pretty small network for them. We have about 2,000 endpoints.
How are customer service and support?
I have used their support. I would rate them a four out of five.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used to have Check Point. We switched because there were a lot of added features with Palo Alto that Check Point didn't have. It was an upgrade for us.
How was the initial setup?
It is incredibly complex. It has a lot of parts. Its implementation took six months.
What about the implementation team?
We worked with Palo Alto directly to look at our old firewalls and translate their configuration to Palo Alto.
There are three of us for deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff.
What other advice do I have?
You get out what you put in. So, the more you work with it, customize it, monitor it, and manage it, the more you'll get out of it.
I would rate it an eight out of ten. There are some bug updates that they were having issues with. Everything else has been pretty great. There is a lot more visibility than I expected.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Vice President / Chief Technology Officer at Sinnott Wolach Technology Group
A stable, scalable, and user-friendly solution that comes with good support and stitches everything together to provide the actual complete picture
Pros and Cons
- "The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
- "A little bit more automation would be nice."
What is our primary use case?
We use it for our own company as well for our clients. It is mainly used for protecting the endpoints. Like everybody else nowadays, we're all working from home, and we have access to data on the public cloud, private cloud, and on-prem. We got to make sure that we're not exposing our endpoints to anything out there that could be malicious and that could cause any problems within our networking environment.
How has it helped my organization?
It has absolutely improved the way our organization functions. We are more secure. It is giving us more peace of mind, and it is doing what it is doing. It has found malicious activity happening on our endpoints that probably would not have been detected if we didn't have it.
What is most valuable?
The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly.
The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that.
What needs improvement?
A little bit more automation would be nice.
For how long have I used the solution?
We've been a reseller for Palo Alto for 13 years. I have been using it for quite a while. They had bought Cyvera for the endpoint security, which was obviously the base for Cortex XDR. I have been seeing how it actually progressed from just a straight endpoint security solution that was a little clunky at one time to a very streamlined, effective solution today.
What do I think about the stability of the solution?
It is stable. I haven't found any issues.
What do I think about the scalability of the solution?
It is extremely easy to scale. We have about 20 users, and their roles stem from sales to technical, marketing, and administrative.
How are customer service and technical support?
Palo Alto has got very good tech support. I would give them a ten out of ten.
Which solution did I use previously and why did I switch?
At one time, I tried Cylance, and it just wasn't that effective for what we needed. At the time, it wasn't really an EDR solution.
How was the initial setup?
The initial setup was very straightforward and easy.
What's my experience with pricing, setup cost, and licensing?
Its pricing is kind of in line with its competitors and everybody else out there.
What other advice do I have?
You don't have to be a Palo Alto customer to implement this solution. Some people think they have to, but no. It is a completely separate solution on its own. I would highly recommend it just because it is a complete package. It not only takes in data from your endpoint; it also takes in data from other sources that are not Palo Alto and helps to create the story about what's going on by stitching things together.
I would rate Cortex XDR a nine out of ten. It is pretty good. The reason for giving a nine is that there is always room for improvement.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Cybersecurity Engineer at GFR Media
Improves our endpoint security posture in both performance (no scanning) and protection (NG AI/ML)
Pros and Cons
- "The one feature of Palo Alto Networks Traps that our organization finds most valuable is the App ID service."
- "It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
What is our primary use case?
We use Palo Alto Networks Traps (Version 6) to protect our endpoints against NG malware via behavior analysis, artificial intelligence and machine learning. Both the PA Traps endpoint logs, our PA firewall traffic logs and the Wildfire sandbox are used to provide immediate threat response and feed this information to the PA Threat Intelligence cloud.
How has it helped my organization?
Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms.
What is most valuable?
The one feature that our organization finds most valuable is being able to control the USB ports on the endpoints
What needs improvement?
The MAC agent is not as robust feature-wise as the PC version. I need to control USB ports on MAC laptops and cannot. This is a MUST so I opened a case with Palo Alto and requested this feature for an upcoming update.
I would like to see more automation and self-healing for incidents that can be easily classified as malware.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
No issues
What do I think about the scalability of the solution?
Palo Alto Networks Traps features excellent protection, cost and scalability. We are a small group of 4 employees and have 2 people dedicated to deployment and monitoring of 1400+ endpoints.
How are customer service and technical support?
Palo Alto Network's technical support is excellent.
Which solution did I use previously and why did I switch?
Since we were a Fortinet shop, we previously used the FortiClient endpoint agent. We switched to Palo alto FWs and endpoint protection because it is a more mature product with advanced next-gen capabilities not available from the Fortinet solution.
How was the initial setup?
The initial setup was done by a Palo Alto certified service provider.
What was our ROI?
This product pays for itself with only one ransomware denial!
What's my experience with pricing, setup cost, and licensing?
Our license runs on a monthly basis with a recurring monthly charge. If you want additional options like secure remote access with policies, that requires an additional cost.
Palo Alto Networks Traps does not apply secure remote access to devices without policies, which we are implementing. If you want to apply more policies, like an anti-virus program, anti-malware, or configurations for using a VPN on remote connections, that would also be an additional cost. We're not doing that.
Which other solutions did I evaluate?
Cylance, Carbon Black, Crowdstrike, Microsoft Windows Defender ATP, Sophos, SentinelONE
What other advice do I have?
On a scale from 1-10, I would rate Palo Alto Networks Traps with an eight. It is great, but I have some issues with the cost of the product license.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT-Administration at a mining and metals company with 51-200 employees
Offers a complete overview of all our PCs and it's very easy to handle and use the interface
Pros and Cons
- "We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us."
- "Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
What is most valuable?
We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us.
What needs improvement?
The one area which should improve is not on the user side but on the product itself. Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats. For example, if you had something that was not detected by the former solution, and you install Palo Alto, you will have some difficulty removing the virus with the Palo Alto tool. It would be helpful if they had a tool for removing a virus or threat in these cases.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is very stable. We have about 350 licenses across all our PCs, and of course, only administrators are allowed to plug in.
What do I think about the scalability of the solution?
Scalability is not an easy question. For us, Palo Alto traps is running on a good environment, so if we have a plan to expand we just adjust the environment and from the Palo Alto side, it is not a problem at all. The only thing I have to do is update the license file and it should work. But in the case of a bigger expansion, you have to separate the servers. For us, it is not a problem at all if we decide to scale Palo Alto traps.
How are customer service and technical support?
Support response was very fast. I'm satisfied with the support.
How was the initial setup?
If you have been educated in Palo Alto, the initial setup is very easy. Without an education it depends. It can be difficult, it depends on the knowledge of the installer.
What other advice do I have?
We use the on-prem version, not the cloud version of Palo Alto.
We use it daily but we have logs. Normally, if we have an incident in detection from a wire system, there's more effort. But typically it would take about ten minutes in order to check the logs and it's not complex at all. But if you have some threats or viruses then, of course, maintenance takes longer.
In terms of advice, I'd say it depends on the usage of the PCs. For us to use in the main production, Palo Alto benefited us. It was easy to install and performance of the traps themselves are very good. In most cases, you don't have to worry about the performance of the PC at all. Palo Alto Traps takes up very few resources.
I would rate this solution 9 out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Servicio Posventa at a security firm with 11-50 employees
A pinpoint evasive threats with patented behavioral analytics solution with a useful policy extension feature
Pros and Cons
- "One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
- "I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
What is our primary use case?
Our clients want to correlate information they have in their network. Many engineers or companies have different tools like CMs, firewalls, VPNs, and some other things related to networks. They mentioned that after they acquired the Cortex XDR solution they have all of the information in one place. That is important because they improved the time to solve security issues.
What is most valuable?
One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers.
Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network.
What needs improvement?
I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs.
For how long have I used the solution?
I have worked with Cortex XDR by Palo Alto Network for about four years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Network is a stable solution. I have been working with it for years, and it only went down once.
On a scale from one to ten, I would give stability a nine.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Network is a scalable solution.
How are customer service and support?
Technical support is okay.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and not very complicated. I think it takes about two hours to deploy this solution. The number of personnel needed depends on the company. For example, banks usually have five cybersecurity engineers installing and maintaining this solution.
On a scale from one to ten, I would give the initial setup a seven.
What's my experience with pricing, setup cost, and licensing?
I don't like that they have different types of licenses.
On a scale from one to nine, I would give licensing costs a seven.
What other advice do I have?
I consider Cortex XDR by Palo Alto Network a good solution. They have good support, and they listen to customer feedback.
On a scale from one to nine, I would give Cortex XDR by Palo Alto Network a nine.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior IT Specialist at a manufacturing company with 1,001-5,000 employees
Useful for monitoring, but its implementation is quite complex
Pros and Cons
- "Monitoring is most valuable."
- "In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
What is our primary use case?
It has just been about a month.
How has it helped my organization?
It is mainly for monitoring and/or logging. We look at it to see if there are any log incidents.
We are using its latest version. It is deployed as a hybrid.
What is most valuable?
Monitoring is most valuable.
What needs improvement?
In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex.
In terms of new features, we don't have any functions or features that we would like to add at the moment.
What do I think about the scalability of the solution?
It is looking promising in terms of scalability, but we have not looked into it further because we are still in the process of learning and getting some experience.
Currently, there are just two users of this solution. They are IT specialists.
How was the initial setup?
Its initial setup is quite complex. In terms of complexity, I would rate it a four and a half out of five.
What's my experience with pricing, setup cost, and licensing?
I am using the Community edition.
What other advice do I have?
My advice for people who are looking into implementing this system is that they should be aware of the complexity of the installation and the management of the system. I would preferably buy this from a partner.
We have not yet completed our review of the product. At this time, I would rate it a five out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Technology Corporate Manager at a consumer goods company with 1,001-5,000 employees
Easy to use, light on resources, and reliable
Pros and Cons
- "Cortex XDR by Palo Alto Networks is easy to use and does not consume a lot of hardware resources."
- "We have found that there are times Cortex XDR by Palo Alto Networks does not detect some of the viruses, we have to use another protection solution called Kaspersky."
What is our primary use case?
We are in the testing stage of using Cortex XDR by Palo Alto Networks. We are using it in order to ensure the corporate network servers are protected. Additionally, we need to use a specialized tool.
What is most valuable?
Cortex XDR by Palo Alto Networks is easy to use and does not consume a lot of hardware resources.
Cortex analyzes the network and users to detect additional risks and threats that the other vendor's solutions don't detect.
What needs improvement?
We have found that there are times Cortex XDR by Palo Alto Networks does not detect some of the viruses, we have to use another protection solution called Kaspersky.
The tool should have the ability to test an environment to see what percentage it is secure against threats, such as ransomware. This would allow for adjustments to be made to the network for more security. We don't have the capability to test the networks daily there should be a parameter in order to report on the healthy of the network for security vulnerabilities.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately two weeks.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is highly stable.
We don't have any user reports suggesting that there is a high level of resource consumption.
What do I think about the scalability of the solution?
In regard to the scalability, the tool could have additional agents to provide a full installation in the company. This would make the installation much easier when scaling the solution, we should not have to use another tool.
The installation approach is to do it one computer at a time, but if Cotex could provide an additional tool in order for us to reach all the elements of the network would be very helpful. It should be done automatically. I understand that if the tool has the capability to analyze the network, it should be able to read the computers' elements in the network and in other ways.
How are customer service and support?
The support is very efficient and professional. They have provided us with the tools and the basic elements to understand how the solution works. They have helped us prepare some specifics for our installation.
Which solution did I use previously and why did I switch?
We use the Kaspersky protection solution. Kaspersky works based on blacklists, if you are on the blacklist it is working well but if you are not Kaspersky does not work.
How was the initial setup?
The installation of Cortex XDR by Palo Alto Networks is easy. The setup is not complicated.
It would be a good idea for the company to provide at their website videos that are translated in Spanish related to technical skills. This would be very useful and would have a lot of value.
The world in commercial terms, speaks English, we have to understand that with tools such as this, if the solution was in other languages more companies would be able to exploit the tool. If we don't have this information in our native language, we will not use the tool to its full potential.
What's my experience with pricing, setup cost, and licensing?
In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage.
I recommend that the company review the pricing model in the Latin American market. They need to determine how to impose, or how to bring a more accessible cost in order to accelerate the implementations in American countries.
Which other solutions did I evaluate?
We have been comparing Cortex XDR by Palo Alto Networks to Cisco solutions.
What other advice do I have?
It is important to have security tools in order to review, monitoring and hunt the potential attacks. We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool.
It's an efficient solution. I recommend this solution to my business partners and other companies.
I rate Cortex XDR by Palo Alto Networks a ten out of ten.
Other solutions I have used I would rate a seven out of ten. There is not something that comes close to this solution.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?