Try our new research platform with insights from 80,000+ expert users
Team Lead at MindTree
Real User
Setup is easy, detects malicious binaries, and is stable
Pros and Cons
  • "One thing that I like about Cortex XDR by Palo Alto Networks, it is detecting all the suspicious or malicious binaries, and it has integration with Palo Alto Firewall."
  • "The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part."

What is our primary use case?

We are using Cortex XDR by Palo Alto Networks as an endpoint solution.

What is most valuable?

One thing that I like about Cortex XDR is its ability to detect all the suspicious or malicious binaries, and it can integrate with Palo Alto Firewall. 

For how long have I used the solution?

I have been using the product for about three and a half years.

What do I think about the stability of the solution?

The stability is very good.

Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.

What do I think about the scalability of the solution?

It is scalable for those who use it.

Which solution did I use previously and why did I switch?

If they want to do a POC, they can look for other market trenders that are there like Trend Micro. They also have their XDR solution. FireEye also has its XDR solution. They should do a comparison on what is based on their requirement. Based on their requirement, they should select the vendor. We saw that there were quite a few ransomware attacks that were not detected by traditional antivirus, so we moved to the Palo Alto solution. Likewise, the companies who want to implement EDR solutions, have to look at the problem statement. Based on their problem statement, they should work and find out a feasible solution.

What's my experience with pricing, setup cost, and licensing?

The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well. That is something that they have to look at going forward.

It took around three to four weeks, because there was a full process change, and then we had to get approval for getting it deployed. 

What other advice do I have?

I would rate Cortex XDR by Palo Alto Networks a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
SOC Manager at Nais Srl
Real User
Good dashboard, and is easy to use, but is not very informative, or complete
Pros and Cons
  • "The information the dashboard provides is very clear."
  • "When it comes to core analysis, and security analysis, Cortex needs to provide more information."

What is our primary use case?

I am an integrator. I deploy and implement solutions for our customers.

What is most valuable?

It is a simple platform to use.

The dashboard is good, it's very clean and very simple to read. The information the dashboard provides is very clear.

What needs improvement?

This solution is not complete enough to help us. We use a different platform that provides us with more information.

In my opinion, it is not a very complete program. I prefer to work with Carbon Black. It's a better solution as well as Cynet. For example, I use Cynet when I check installations, which provides me with more information. It is not easy to use for beginners, but it provides me with more information, which is lacking in Cortex. When it comes to core analysis, and security analysis, Cortex needs to provide more information. Cynet is a complete platform in my opinion.

We are ready to use a new solution called Deep Instinct. It's a new concept of the security platform. It's a very new company from the USA.

I would like to see a feature that allows you to check the endpoints included. I am currently having trouble checking the endpoints when using Cortex. Including this feature would benefit the platform's endpoints.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is absolutely stable.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is a scalable platform.

Which solution did I use previously and why did I switch?

I am currently using QRadar in more than one enterprise, as well as Cynet, and Darktrace. We also use all of the Microsoft platforms with QRadar.

I have a team working on this solution. So I assisted a customer in deploying and implementing this solution. My colleague and I have formed a team. I am a SOC manager, my new role is that of a SOC manager. I don't use it directly, but I try to assist my colleague in working with more enterprises or customers. We have, I believe, five or six different IBM QRadar platforms.

We use several solutions and they are all good, but each one is different.

Cynet is a good platform, but helpful for my team because it is not simple to understand.

What other advice do I have?

I would rate Cortex XDR by Palo Alto Networks a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
January 2025
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Zubair Ahmad - PeerSpot reviewer
Senior Chief Manager at Arcil
Real User
Top 10
Stable, scalable, and best for avoiding security issues
Pros and Cons
  • "Best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
  • "Limited remote connection."

What is our primary use case?

I primarily use Cortex XDR for endpoint security.

How has it helped my organization?

PALO ALTO CORTEX XDR brings visibility of all activity going in end point system and server. This helps us to investigate and take corrective action by blocking and allowing necessary services in the system. 

What is most valuable?

Alerts regarding the incidence happening in system and easy to block and allow the services and external device control.

What needs improvement?

An area for improvement is the remote connection for administrators - this is available in the current version but is limited as it's a command-based model rather than GUI-based.

For how long have I used the solution?

I have been using Cortex XDR for around four months.

What do I think about the stability of the solution?

Cortex XDR is stable.

What do I think about the scalability of the solution?

The product is really easy to scale.

How are customer service and support?

Good support and services

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, I used McAfee Antivirus, Memory utilization very high which doesn't yet have virtualization or a dashboard. I found that product to be a little difficult, and it was not linked to a real solution, so I decided to go with Cortex XDR as it's one of the best XDR solutions for security.

How was the initial setup?

The initial setup is a little complex because it requires a lot of preparation in terms of understanding each system and going through the documentation and dashboards.

What about the implementation team?

I implemented with the help of one partner who did the basic configuration of our firewall. Deployment took approximately ten days.

What was our ROI?

Security of systems

What's my experience with pricing, setup cost, and licensing?

This is a very costly product.

Which other solutions did I evaluate?

We have evaluated Cynet, Crowed Strike and Sentinel.

What other advice do I have?

Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues. I would rate this solution as eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Jitendra_Singh - PeerSpot reviewer
Senior Vice President at Chi Networks
Real User
Helps to secure your infrastructure
Pros and Cons
  • "Cortex XDR's most valuable feature is its intelligence-based dashboards."
  • "Cortex XDR could be improved with more GUI features."

What is our primary use case?

I primarily use Cortex XDR to protect end-users from ransomware, malware, spam, and phishing.

How has it helped my organization?

Cortex XDR alerts us on the dashboard when there's a threat, which allows us to restrict that user and helps secure our infrastructure.

What is most valuable?

Cortex XDR's most valuable feature is its intelligence-based dashboards.

What needs improvement?

Cortex XDR could be improved with more GUI features.

For how long have I used the solution?

I've been using Cortex XDR for a year.

What do I think about the stability of the solution?

Cortex XDR is quite stable.

What do I think about the scalability of the solution?

Cortex XDR is scalable.

How are customer service and support?

Cortex XDR's technical support is really good, though their knowledge of endpoint protection could be deeper.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was quite straightforward, and deployment took two to three days.

What about the implementation team?

We used an in-house team.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR's pricing is ok. We pay about $20 a year for our license.

What other advice do I have?

I would give Cortex XDR a rating of eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Digital Business Solutions Manager at Bahrain Telecommunication Company BSC (Batelco)
Real User
A stable and scalable extended detection and response platform, but it would be better if they educated their customers more
Pros and Cons
  • "It's a nice product that's stable and scalable."
  • "It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."

What is our primary use case?

We don't have many customers moving to Cortex XDR by Palo Alto Networks. But recently, we started offering them both pro and basic options. 

What is most valuable?

It's a nice product that's stable and scalable.

What needs improvement?

It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support.

What do I think about the stability of the solution?

The product is stable. Palo Alto only works on security, and the product by default is stable. They are releasing new features, OS, and an ML-based thing on the firewall itself, which is quite impressive. Palo Alto is quite stable compared to other competitors in the market.

What do I think about the scalability of the solution?

It's scalable. I see whatever is written on their datasheets, and all it's real. If I talk to some other vendor and they say that they currently provide 20 Gbps reports, but when you activate it, IPSec and all, it goes to 2 Gbps. With Palo Alto, whatever is there is working, and it's scalable.

How are customer service and technical support?

Technical support is quite good. When compared to others, I feel it's quite impressive.

What's my experience with pricing, setup cost, and licensing?

The price is on the higher side, but it's okay.

What other advice do I have?

I would tell potential users that it's a complete solution from Palo Alto with firewalls and all to give you more precise logs and information. Product-wise, it's top of the line. If you have investment, always go for that and go for the best solution. 

Palo Alto is one of the tech vendors that always provides top-of-the-line products. Price-wise it will be on the higher side, but it depends on how you deal with the backend support or the account manager of Palo Alto to get that discount. 

On a scale from one to ten, I would give Cortex XDR by Palo Alto Networks a seven.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Ragesh Singh - PeerSpot reviewer
Cyber Security Engineer at ACPL
Real User
Performs stitching between a number of security domains
Pros and Cons
  • "We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
  • "Cortex XDR should have a lightweight agent, and the agent size should not be heavy."

What is our primary use case?

Cortex XDR does the stitching between a number of security domains, like email security, API security, and web security. The solution does the stitching from different sources and makes a logical incident.

What is most valuable?

We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action. We don't need to navigate different solutions and tools or use our human intelligence to correlate all the information to make the logic. Cortex XDR entirely does it, and we can take action.

What needs improvement?

Cortex XDR should have a lightweight agent, and the agent size should not be heavy. Cortex XDR’s technical support should also be improved.

Cortex XDR should provide a feature to remove or uninstall an agent directly from the console itself without the help of an IT engineer. No one wants to do a manual installation of the agent. Everyone is looking for a solution to remove the agent from the console directly.

For how long have I used the solution?

I have been working with Cortex XDR by Palo Alto Networks for two years.

What do I think about the stability of the solution?

I rate Cortex XDR a ten out of ten for stability.

What do I think about the scalability of the solution?

I rate Cortex XDR a five out of ten for scalability.

How are customer service and support?

The technical support of Cortex XDR and other OEM products is not very good. Cortex XDR's technical support does not usually respond quickly.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate Cortex XDR’s initial setup an eight out of ten.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR’s pricing is very reasonable. I rate Cortex XDR a five out of ten for pricing.

What other advice do I have?

I am using the latest version of Cortex XDR by Palo Alto Networks. Cortex XDR is usually deployed in our clients’ organization on cloud. The time it takes to deploy Cortex XDR depends totally upon the organization.

The biggest drawback of Cortex XDR is that it has a heavyweight agent. Cortex XDR would be a good product if this issue could be resolved.

Overall, I rate Cortex XDR an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Dennis Ngetich - PeerSpot reviewer
Cloud Specialist at Eazzy Solutions
Reseller
Scalable and high availability
Pros and Cons
  • "Cortex XDR by Palo Alto Networks should be a stable solution."
  • "Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."

What is our primary use case?

Cortex XDR by Palo Alto Networks is a network management solution.

What needs improvement?

Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console.

For how long have I used the solution?

I have sold Cortex XDR by Palo Alto Networks within the last 12 months.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks should be a stable solution.

What do I think about the scalability of the solution?

The scalability of Cortex XDR by Palo Alto Networks is very good.

What's my experience with pricing, setup cost, and licensing?

The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month.

What other advice do I have?

I would recommend this solution to others.

I rate Cortex XDR by Palo Alto Networks an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
reviewer1704321 - PeerSpot reviewer
Cloud and Security Architect at a transportation company with 51-200 employees
Real User
Robust with powerful security correlation features
Pros and Cons
  • "The stability of this product is very good."
  • "It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."

What is our primary use case?

Security correlation is our main use case.

What needs improvement?

This product could be simpler to use. For example, the onboarding process and getting it started could be improved.

The technical support is in need of improvement.

For how long have I used the solution?

I have been working with Cortex XDR by Palo Alto Networks for one year.

What do I think about the stability of the solution?

The stability of this product is very good.

What do I think about the scalability of the solution?

Scalability-wise, this is a very good solution. We have 100 people using it across a variety of roles. It's deployed for everybody, although it's only actively used by myself and one other person.

Our company size is quite static so I don't expect that we will increase our usage.

How are customer service and support?

The technical support is not very good. I find the process difficult. It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable.

Which solution did I use previously and why did I switch?

I also use Sophos Intercept X.

How was the initial setup?

The initial setup is complex. On a scale of one to five, I would rate the complexity a three. It took six months to deploy.

What about the implementation team?

We implemented this product in-house.

What other advice do I have?

My advice for anybody who is implementing this product is to ensure that the project plan has appropriate troubleshooting time in it.

Overall, I'm quite happy with the product.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.