We use Palo Alto Traps in our Windows-based environments. Currently, it only protects our desktops and we use it in conjunction with our Check Point firewall.
Senior System Administrator at a government with 10,001+ employees
WildFire AI helps detect and prevent threats, but the dashboard should be more intuitive
Pros and Cons
- "WildFire AI is the best option for this product."
- "The dashboard is the area that needs to improve so that we can have the ability to drill down without having to go elsewhere to verify results."
What is our primary use case?
How has it helped my organization?
The product is very good, it has caught a lot of exploits that most products would not. The WildFire module is a great AI in detecting and preventing attacks. The only issues that we have are, one the cost, two the dashboard is not very intuitive, even though you can drill down within the dashboard, we usually have to gather information from other sources to determine locations and if its a false positive.
What is most valuable?
WildFire AI is the best option for this product.
What needs improvement?
The dashboard is the area that needs to improve so that we can have the ability to drill down without having to go elsewhere to verify results.
Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
We have had this product for two years.
What's my experience with pricing, setup cost, and licensing?
This is an expensive solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Head of Network and Communication Department at a program development consultancy with 10,001+ employees
The level of security I get for my endpoints and servers is extremely valuable.
What is most valuable?
The level of security I get for my endpoints and servers is extremely valuable.
How has it helped my organization?
No signature updates of the AV needed, so no old signatures. No patching, very little operational effort needed.
What needs improvement?
Performance at the endpoint is much better than with the old AV.
No signature updates needed.
Stops the attack before it is executed.
For how long have I used the solution?
Two years.
What was my experience with deployment of the solution?
No.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
Perfect.
Technical Support:Real experts.
Which solution did I use previously and why did I switch?
Yes. We switched because the footprint was heavy, the protection rate decreases and the operational costs (incidence response) were high.
How was the initial setup?
Yes, it took one hour to install the back end and the rollout was done by software deployment. Project lasted four weeks .
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
Ask your local dealer.
Which other solutions did I evaluate?
Yes.
What other advice do I have?
If you are already a Palo Alto Networks Firewall customer you can have perfect Integration between your clients/servers and your firewalls. Automated response without supporting and APIs.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Cortex XDR by Palo Alto Networks
February 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Cybersecurity Services Director at ITVikings
Stable platform with good technical support services
Pros and Cons
- "We can visualize and control the activities in the environment from anywhere."
- "The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."
What is our primary use case?
We use the product to monitor and control all the systems. It helps us understand user behavior.
How has it helped my organization?
The product gives full visibility and control of the endpoints in the environment. The users and the employees can protect their systems by investigating files for incidents.
What is most valuable?
The platform's most valuable feature is being a cloud-based solution. We can visualize and control the activities in the environment from anywhere.
What needs improvement?
The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced.
For how long have I used the solution?
We have been using Cortex XDR by Palo Alto Networks for two months.
What do I think about the stability of the solution?
The platform is stable. As far as you have the internet, the product is secure.
What do I think about the scalability of the solution?
The platform is scalable.
How are customer service and support?
They have a good technical support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. It is easy to maintain as well.
What about the implementation team?
I implemented the product myself.
What other advice do I have?
I recommend Cortex XDR by Palo Alto Networks and rate it an eight out of ten. It is a good solution for the commercial sector as they can work on the cloud. I advise others to refer to user guides for understanding the processes easily.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
EMEA IT Infrastructure Manager at a consumer goods company with 5,001-10,000 employees
Good management capabilities but has poor performance
Pros and Cons
- "The management capabilities, allow an IT organization to get quite a good picture of attempted cyber attacks."
- "Impact on system performance is horrible, adding a lot of delays for users."
What is our primary use case?
My primary use of this solution is as an endpoint security client.
How has it helped my organization?
This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance.
What is most valuable?
The most valuable features of this product are the management capabilities, which allow an IT organization to get quite a good picture of attempted cyber attacks, and its out-of-the-box investigation capabilities.
What needs improvement?
The product's impact on system performance is horrible, adding a lot of delays for users.
For how long have I used the solution?
I have been using this solution for four months.
How was the initial setup?
The onboarding process was quite cumbersome. It took some time to deploy as we had to investigate about 500 cases of clients who did not get the agent immediately.
What about the implementation team?
I implemented using a vendor team.
What other advice do I have?
I would rate this solution as five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Lead Security Engineer at ESKA
Scalable with excellent protection features and is very user-friendly
Pros and Cons
- "The solution doesn't need a high level of technical training."
- "Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
What is our primary use case?
Cortex XDR is used for endpoint detection and response. This is software placed into endpoints and work in this cloud. In cloud has the analytics, login, prevention models, et cetera.
What is most valuable?
If a company uses Palo Alto and supports Cortex XDR for endpoint protection it is very well protected. Palo Alto is the best security solution in the market. It's very advanced and its protection is extremely reliable.
The solution doesn't need a high level of technical training. The solution is very usable and doesn't take a lot of personnel.
The product is very scalable.
The stability is very good.
What needs improvement?
For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible.
Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well.
For how long have I used the solution?
I've been working with this security solution for ten years or so and Palo Alto Networks for two years.
What do I think about the stability of the solution?
The solution has been very stable and very reliable. There are no bugs or glitches. It doesn't crash or freeze. It's one of the best on the market.
What do I think about the scalability of the solution?
The solution is very scalable. It works well for companies that are quite sizeable. If an organization needs to expand it, it can do so easily.
We have about 50 to 55 users on the solution.
How are customer service and technical support?
I personally handle technical questions for those working with Palo Alto.
Support of Palo Alto is English, however, I work in this local technical solution, local technical and I'm working with customers with a warranty.
I've found technical support from Palo Alto to be very good. We're local and we can assist as well, however, Palo Alto is capable of handling any size of issue and they are quite helpful.
How was the initial setup?
I am not directly handling the installation. My client is.
You do need a team of people on this solution that understand the cloud and the solution itself if you have a large, complex environment. If you have a robust security team, it's good. However, if you don't have the resources, it's not an ideal product.
That said, if your company requires a small, simple setup, one person may be enough. It really depends on the size.
What about the implementation team?
My client is actually handling the installation. I often field questions from them, however, I don't participate in the installation directly.
What's my experience with pricing, setup cost, and licensing?
For basic needs, the solution isn't very expensive. However, as you grow more complex in your needs, the more you use, the more costly it can get.
The licensing is typically for one year. There's a one-time installation. If you would like to continue with the service, you can continue. There's no need to install and reinstall.
What other advice do I have?
Cortex XDR is a threat analytics security manager that allows users to see what threats are going to endpoints. It's a very high-security solution.
The next step up from Cortex XDR is Cortex XSOAR. XSOAR is an automated threat solution. It's a security solution from Palo Alto.
I'd recommend the solution to others. I'd rate it at a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Information information analyst at Seeton
It's a simple platform that's easy for administrators and users
Pros and Cons
- "Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features."
- "The playbooks could be improved to include more functionalities or actions."
What is most valuable?
Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features.
What needs improvement?
The playbooks could be improved to include more functionalities or actions.
For how long have I used the solution?
I have been using Cortex XDR for a few months.
What do I think about the stability of the solution?
Cortex XDR is highly stable.
What do I think about the scalability of the solution?
Cortex XDR is scalable.
Which solution did I use previously and why did I switch?
We previously used McAfee, but we switched because of our customer. We checked Gartner's to learn about each vendor and solution and consulted with the customer about the features they needed.
How was the initial setup?
Cortex XDR is a cloud-based solution, so the deployment is straightforward. They give you your credentials to access the platform and you change some settings to customize it.
What other advice do I have?
I rate Cortex XDR by Palo Alto nine out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sales Engineer at a security firm with 51-200 employees
Reliable with good support, but the installation should be simplified
Pros and Cons
- "Stability is one of the features we like the most."
- "The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
What is our primary use case?
We use this solution to secure endpoints and to have more visibility on what is happening on the endpoints.
We have two customers who are using this solution currently.
What needs improvement?
The installation should be easier and the Palo Alto pre-sales and sales should teams have more information on the product because they don't know what they are selling.
They don't know the features of the products they sell.
For example, Cortex XDR includes Cortex XDR Prevent, Cortex XDR Pro, and Cortex XDR Pro per TB. They don't know the real differences between Cortex XDR Pro and Cortex XDR Pro per TB.
Sometimes, they will tell you about features for one edition that belong to another edition. They don't seem to know what features belong to what edition.
For how long have I used the solution?
I have been working with this solution for one month.
We are familiar with Cortex XDR Prevent and Cortex XDR Pro.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
How are customer service and technical support?
Technical support is okay.
How was the initial setup?
The initial setup is complex. It is not easy to install.
We have been deploying this solution for a month, but we are not finished yet.
We only need one engineer for the deployment and maintenance.
What other advice do I have?
I would recommend this solution to anyone who is interested in using it.
I would rate Cortex XDR a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Business Development Manager at a tech services company with 201-500 employees
Efficiently detects any issues
Pros and Cons
- "This software helps us understand any issues that may arise when someone is not at work."
- "Dashboards do not allow everyone to see what's happening."
What is our primary use case?
It is used as a device that can detect any issues and changes when people are not at work. In one case, we use it when someone is not at work or has already used their allotted time off. This helps us understand any issues that may arise when someone is not at work, which could lead to changes in the way we work.
What needs improvement?
There are many areas that could use improvement. One thing that is important to keep in mind is that times change, and we need to be adaptable to what happens. Ultimately, we want to see positive results and improvements.
In the next release, I would add dashboards that allow everyone to see what's happening, not just the security team. Users can view the data and see what's happening. Also, I think the Data Lake from Cortex XDR should be public, not private.
For how long have I used the solution?
I have been using the solution for two years.
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
The pricing is cheap.
What other advice do I have?
I rate it a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?