We are using Cortex XDR by Palo Alto Networks as an endpoint solution.
Team Lead at MindTree
Setup is easy, detects malicious binaries, and is stable
Pros and Cons
- "One thing that I like about Cortex XDR by Palo Alto Networks, it is detecting all the suspicious or malicious binaries, and it has integration with Palo Alto Firewall."
- "The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part."
- "One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well."
What is our primary use case?
What is most valuable?
One thing that I like about Cortex XDR is its ability to detect all the suspicious or malicious binaries, and it can integrate with Palo Alto Firewall.
For how long have I used the solution?
I have been using the product for about three and a half years.
What do I think about the stability of the solution?
The stability is very good.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It is scalable for those who use it.
Which solution did I use previously and why did I switch?
If they want to do a POC, they can look for other market trenders that are there like Trend Micro. They also have their XDR solution. FireEye also has its XDR solution. They should do a comparison on what is based on their requirement. Based on their requirement, they should select the vendor. We saw that there were quite a few ransomware attacks that were not detected by traditional antivirus, so we moved to the Palo Alto solution. Likewise, the companies who want to implement EDR solutions, have to look at the problem statement. Based on their problem statement, they should work and find out a feasible solution.
What's my experience with pricing, setup cost, and licensing?
The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well. That is something that they have to look at going forward.
It took around three to four weeks, because there was a full process change, and then we had to get approval for getting it deployed.
What other advice do I have?
I would rate Cortex XDR by Palo Alto Networks a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior System Administrator at a government with 10,001+ employees
Makes it easy to isolate endpoints and lets us know if something needs to be addressed
Pros and Cons
- "Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them."
- "I don't have to do much monitoring with it; I don't have to have anybody manually looking at this, it gives us reports, and it lets us know if something needs to be addressed, and we can easily address it."
- "We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
What is our primary use case?
We use it to make sure that our antivirus is up to par.
It used to be on-prem, but now, it's completely on the cloud. In terms of the version, we've got some old endpoints that we had to manually bring up to date, but for the most part, it's up to date.
How has it helped my organization?
I don't have to do much monitoring with it. I don't have to have anybody manually looking at this. It gives us reports, and it lets us know if something needs to be addressed, and we can easily address it. I've been pleased with it. It's been a really good product for us.
What is most valuable?
Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them. The hash that they use is pretty comprehensive. I like WildFire. It gives us a better idea of what is a true virus and what is a false positive.
What needs improvement?
We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do.
For how long have I used the solution?
We've been using it for at least three years.
What do I think about the stability of the solution?
It has been stable. I have not had any issues with it.
What do I think about the scalability of the solution?
For our use, we didn't need scalability with it. It has just been working as we needed it to work.
How are customer service and support?
The only time we had to deal with their support was when we had a problem with getting our older endpoints up to date. They made the upgrades and gave us the solutions on what we needed to do, and that has been working for us.
How was the initial setup?
It was pretty straightforward, and now that it does an automatic update, I don't even have to remember to update it anymore. Once a definition expires, it automatically goes in and puts in the newest definitions, and updates all the endpoints. It is way better than what it used to be.
What's my experience with pricing, setup cost, and licensing?
I don't recall what the cost was, but it wasn't really that expensive.
What other advice do I have?
The only thing I would advise is to get a solution for which you don't have to do a lot of monitoring. It helps when we don't have to have an extra person to manually go through and look at each endpoint to make sure things are up to date and all definitions are up to date.
I would rate it a nine out of ten because it's a really stable platform, and it is doing everything that I need it to do. You can always have improvement, but I'm really not sure what that improvement would be.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
896,942 professionals have used our research since 2012.
CISO at International Bank of Azerbaijan
Provides great security with its machine-learning technology and behavior-based analytics features
Pros and Cons
- "Palo Alto is constantly adding new features."
- "These days it's machine-learning technology and behavior-based analytics features that make us more secure."
- "The solution lacks real-time, on-demand antivirus."
- "There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state."
What is our primary use case?
This solution has replaced our traditional antivirus solutions; it protects our environment and safeguards our endpoints from any malware or exploitation. We are based in Azerbaijan, I'm the CISO of the company and we are customers of Palo Alto.
How has it helped my organization?
We've seen benefits because the solution includes a big data approach to cyber security. All information is collected from the network, the endpoints, and the logs and analyzed by applying a big-data approach that shows up anomalies.
What is most valuable?
I chose this solution because they constantly add new features and are very proactive about that. To my mind, signature-based antivirus is a thing of the past. These days it's machine-learning technology and behavior-based analytics features that make us more secure. XDR feels secure because of those features.
What needs improvement?
There are still a few gaps with this solution. For example, real-time, on-demand antivirus is not there. If you're looking for compliance XDR is somewhat lacking. There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state. That is currently lacking in XDR.
For how long have I used the solution?
I've been using this solution for about two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
This solution is scalable.
How are customer service and support?
We have premium Palo Alto support and they provide good service.
How was the initial setup?
The initial setup is straightforward.
What other advice do I have?
I think any XDR technology is best for protecting an environment from cyber attacks. The visibility it provides is crucial and XDR gives us that, we can see all effect vectors.
I rate this solution eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Specialist at a manufacturing company with 1,001-5,000 employees
Useful for monitoring, but its implementation is quite complex
Pros and Cons
- "Monitoring is most valuable."
- "In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex."
- "Based on our experience so far, its implementation is quite complex."
What is our primary use case?
It has just been about a month.
How has it helped my organization?
It is mainly for monitoring and/or logging. We look at it to see if there are any log incidents.
We are using its latest version. It is deployed as a hybrid.
What is most valuable?
Monitoring is most valuable.
What needs improvement?
In terms of areas of improvement, we have not completed our review of the product. We're also looking at other products. So, it's a little bit hard to tell what could be different because we have not completed the review of this product, but based on our experience so far, its implementation is quite complex.
In terms of new features, we don't have any functions or features that we would like to add at the moment.
What do I think about the scalability of the solution?
It is looking promising in terms of scalability, but we have not looked into it further because we are still in the process of learning and getting some experience.
Currently, there are just two users of this solution. They are IT specialists.
How was the initial setup?
Its initial setup is quite complex. In terms of complexity, I would rate it a four and a half out of five.
What's my experience with pricing, setup cost, and licensing?
I am using the Community edition.
What other advice do I have?
My advice for people who are looking into implementing this system is that they should be aware of the complexity of the installation and the management of the system. I would preferably buy this from a partner.
We have not yet completed our review of the product. At this time, I would rate it a five out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Consultant at Trillennium (Pvt) Ltd
Excellent technical support, straightforward implementation, and cutting-edge technology
Pros and Cons
- "When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
- "Technical support is the best in class, in my opinion, because they have invested heavily in research and development."
- "In general, the price could be more competitive."
What is our primary use case?
We are not using it for our purposes because we are a Palo Alto partner. We propose it for our customers based on their requirements.
We are both a service provider and a reseller.
When the pandemic first began, the use cases were mostly for remote users. We deployed this for the majority of remote users.
What is most valuable?
When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud. We have a lot of advantages as a result.
It's a very simple implementation, and I have direct Palo Alto implementation available as well. So it's very simple. We haven't found any issues, so far the implementation is going well, I don't see any gaps.
What needs improvement?
In general, the price could be more competitive.
For how long have I used the solution?
In Palo Alto, we also work with all product lines, including Prisma and other product lines as required. Is a mix, it's a subproduct, we work with the mix of products.
We have been working with Cortex XDR by Palo Alto Networks for two to three years.
We get updates from Palo Alto directly.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is a stable product.
What do I think about the scalability of the solution?
It's a scalable solution, we have not had any challenges with the scalability of Cortex XDR by Palo Alto Networks.
Our customers range from medium to large enterprise companies. The adoption rate in small businesses is much less, but the majority of our requirements come from mid-to enterprise-sized businesses.
How are customer service and support?
Technical support is the best in class, in my opinion, because they have invested heavily in research and development. In terms of comparison and today's challenges, such as security and layers, Palo Alto complies with all of the challenges.
Which solution did I use previously and why did I switch?
In terms of Security, we are working with a few products and a few brands.
We use Palo Alto and we also work with Barracuda. These solutions are used on the web firewall and for email protection.
We work with the entire Barracuda product line, but specifically for email protection and web filtering.
Barracuda Essentials is included with O365 protections, we work with those solutions.
Palo Alto is part of a different vertical layer than Barracuda. It's distinct. They are very different.
How was the initial setup?
The initial setup depends on the environment, but as a technology, I would say it's simple. It's not that difficult.
The length of time it takes for deployment is determined by the project and the surrounding environment. We can only determine the timeframe based on that, pinpointing a specific time period is difficult.
It does not require maintenance because regular updates and monitoring are required. So if there is anything, new patches and the like, it is done automatically, and there is no additional implementation unless there are any infrastructure changes.
What's my experience with pricing, setup cost, and licensing?
In comparison to other competing products, it is based on the customer's needs and the environment. However, when compared to other products, the price is slightly higher, but when considering technology and new innovation, that is the plus I would say when it comes to being XDR.
The price could be more competitive because it is not on the price wall when you go and question Palo Alto XDR. It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable.
What other advice do I have?
So far, it has met all of our requirements, and it should be able to cater to a wide range of product lines.
We must first determine what their business requirements are, as well as what other technical layers we are considering, and then propose the appropriate sizing and solution.
We mostly promote Palo Alto, but it depends on the customer's needs, as well as their budget, infrastructure, and what their business requires, all of those factors come into play when recommending a solution.
When you compare it with other products, I would rate Cortex XDR by Palo Alto Networks a nine out of ten.
It's close to being rated a ten out of ten because of their level of support, and the other is the solution and the most recent technology.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Cloud and Security Architect at a transportation company with 51-200 employees
Robust with powerful security correlation features
Pros and Cons
- "The stability of this product is very good."
- "It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
- "The technical support is not very good. I find the process difficult."
What is our primary use case?
Security correlation is our main use case.
What needs improvement?
This product could be simpler to use. For example, the onboarding process and getting it started could be improved.
The technical support is in need of improvement.
For how long have I used the solution?
I have been working with Cortex XDR by Palo Alto Networks for one year.
What do I think about the stability of the solution?
The stability of this product is very good.
What do I think about the scalability of the solution?
Scalability-wise, this is a very good solution. We have 100 people using it across a variety of roles. It's deployed for everybody, although it's only actively used by myself and one other person.
Our company size is quite static so I don't expect that we will increase our usage.
How are customer service and support?
The technical support is not very good. I find the process difficult. It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable.
Which solution did I use previously and why did I switch?
I also use Sophos Intercept X.
How was the initial setup?
The initial setup is complex. On a scale of one to five, I would rate the complexity a three. It took six months to deploy.
What about the implementation team?
We implemented this product in-house.
What other advice do I have?
My advice for anybody who is implementing this product is to ensure that the project plan has appropriate troubleshooting time in it.
Overall, I'm quite happy with the product.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Key Account Manager at Orange Cyberdefense
Easy to use with excellent root cause analysis and interesting pricing
Pros and Cons
- "I've found the solution to be highly scalable for enterprises."
- "Overall, it's a great platform; it integrates very well with other solutions from Palo Alto and also with our vendors, the ease of use is excellent, I love the root cause analysis from Cortex, which is amazing, and in a few clicks you can have the full root cause."
- "It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
What is our primary use case?
It can work as a standalone solution, however, it also fully integrates with the firewall. It operates on an endpoint level and on firewall level. It's endpoint security, so there are not 35 use cases. It's pretty specific.
What is most valuable?
Overall, it's a great platform. It integrates very well with other solutions from Palo Alto and also with our vendors.
The ease of use is excellent.
I love the root cause analysis from Cortex, which is amazing. It's really fantastic. In a few clicks, you can just have the full root cause.
The price is quite interesting. It's not overly expensive.
The solution is stable.
I've found the solution to be highly scalable for enterprises.
What needs improvement?
What would be interesting, is if it could also read IoT protocols. If they can improve on the IoT part that would be great. In general, in this area, they can still improve.
It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all.
For how long have I used the solution?
The solution is quite new. I've been using it for approximately the last two years. It hasn't been that long just yet.
What do I think about the stability of the solution?
There are no performance issues. It's really very stable. I haven't dealt with bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The product is absolutely scalable. It's an enterprise solution. However, one less positive thing about it, is that it's only from 200 users, from 200 endpoints. That's bad. What do you do with clients who have only 100 endpoints? They cannot purchase Cortex. That has to be improved, with high priority. Palo Alto is aware of that.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite good. It's interesting. It's not a particularly expensive option.
What other advice do I have?
We are using the Cortex Pro version of the solution.
I'd advise users to do a proof of concept (POC) and try it out. It's amazing.
I'd rate the solution at a nine out of ten. It's one of the top solutions on the market. We've been very happy with it so far.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
SOC Manager at Nais Srl
Good dashboard, and is easy to use, but is not very informative, or complete
Pros and Cons
- "The information the dashboard provides is very clear."
- "It is a simple platform to use."
- "When it comes to core analysis, and security analysis, Cortex needs to provide more information."
What is our primary use case?
I am an integrator. I deploy and implement solutions for our customers.
What is most valuable?
It is a simple platform to use.
The dashboard is good, it's very clean and very simple to read. The information the dashboard provides is very clear.
What needs improvement?
This solution is not complete enough to help us. We use a different platform that provides us with more information.
In my opinion, it is not a very complete program. I prefer to work with Carbon Black. It's a better solution as well as Cynet. For example, I use Cynet when I check installations, which provides me with more information. It is not easy to use for beginners, but it provides me with more information, which is lacking in Cortex. When it comes to core analysis, and security analysis, Cortex needs to provide more information. Cynet is a complete platform in my opinion.
We are ready to use a new solution called Deep Instinct. It's a new concept of the security platform. It's a very new company from the USA.
I would like to see a feature that allows you to check the endpoints included. I am currently having trouble checking the endpoints when using Cortex. Including this feature would benefit the platform's endpoints.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is absolutely stable.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is a scalable platform.
Which solution did I use previously and why did I switch?
I am currently using QRadar in more than one enterprise, as well as Cynet, and Darktrace. We also use all of the Microsoft platforms with QRadar.
I have a team working on this solution. So I assisted a customer in deploying and implementing this solution. My colleague and I have formed a team. I am a SOC manager, my new role is that of a SOC manager. I don't use it directly, but I try to assist my colleague in working with more enterprises or customers. We have, I believe, five or six different IBM QRadar platforms.
We use several solutions and they are all good, but each one is different.
Cynet is a good platform, but helpful for my team because it is not simple to understand.
What other advice do I have?
I would rate Cortex XDR by Palo Alto Networks a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Extended Detection and Response (XDR) Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Sentinel
Varonis Platform
Elastic Security
Huntress Managed EDR
HP Wolf Security
TrendAI Vision One
Trellix Endpoint Security Platform
WatchGuard Firebox
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
















