We primarily use the solution for our endpoint server and endpoint protection.
CIO/CTO at a manufacturing company with 501-1,000 employees
Good GUI, however lacks features overall and tends to eat memory
Pros and Cons
- "They have a new GUI which is just fantastic."
- "There's an overall lack of features."
What is our primary use case?
What is most valuable?
There aren't many features we find valuable on the solution.
They have a new GUI which is just fantastic.
What needs improvement?
The solution eats memory of the computer, unlike anything I've ever seen. It eats more memory than Chrome.
I have a lot of users that are eating my memory each hour every day and it's causing us problems. We have to go and buy more memory for each computer. When you have a lot of computers like we do, is not a very good situation.
Some of the computers are only using 4 GB of memory, so if you put aside the differences, most only have some Chrome, some internet, and Office and that's it. And yet, the memory is getting eaten.
If someone catches something like malware, or something else, I want to know if the file was spread to other machines and what the target was. I want to be able to get ahead of the spread. This solution doesn't do enough to protect us against these types of vulnerabilities or to give us much information about the spread. The tool really does need some more reverse engineering features.
There's an overall lack of features.
The initial setup could use improvement. Currently, I must go to each machine and deploy everything manually. We are in 2020, not in 1980. It seems like such a dated way of doing large deployments.
For how long have I used the solution?
I've been using the solution for a year and a half.
Buyer's Guide
Cortex XDR by Palo Alto Networks
December 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
What do I think about the stability of the solution?
When I was experimenting with stability early on, I did run into issues when testing the solution in the sandbox.
Eventually, it catches one of the executive files and if you go to the management section of the solution and you release this file, it takes seven or eight tries to do it. You need to keep trying, again and again, using the same procedures to release the file for usage. That was in the beginning and we still have this issue, even though they made a new GUI for management. It's still not resolved.
What do I think about the scalability of the solution?
We have several hundred users.
I had some issues initially in the sandbox when I was testing scalability.
How are customer service and support?
I have reached out to technical support in the past. I find dealing with them is like talking to a wall. They aren't terrible, however, you don't really get any guidance. They ask over and over to get us to send them dump files and we do over and over. After all of the back and forth, nothing is really resolved to our satisfaction. You're paying for their services, and you don't get the level of service you would expect. It's a pain point.
How was the initial setup?
The initial setup was not complex. It was very straightforward.
The deployment did take a lot of time due to the fact that we had seven hundred computers.
What other advice do I have?
We simply use the solution as a customer.
I would not recommend the solution. I'd advise other companies to rather go with Palo Alto's firewall as a better option. I've already advised others not to touch it. It's not worth it at all to even consider using it.
I'd rate the solution six out of ten. Their new GUI is very nice, however, as a professional service, it's lacking in a lot of areas.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cybersecurity Services Director at ITVikings
Stable platform with good technical support services
Pros and Cons
- "We can visualize and control the activities in the environment from anywhere."
- "The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."
What is our primary use case?
We use the product to monitor and control all the systems. It helps us understand user behavior.
How has it helped my organization?
The product gives full visibility and control of the endpoints in the environment. The users and the employees can protect their systems by investigating files for incidents.
What is most valuable?
The platform's most valuable feature is being a cloud-based solution. We can visualize and control the activities in the environment from anywhere.
What needs improvement?
The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced.
For how long have I used the solution?
We have been using Cortex XDR by Palo Alto Networks for two months.
What do I think about the stability of the solution?
The platform is stable. As far as you have the internet, the product is secure.
What do I think about the scalability of the solution?
The platform is scalable.
How are customer service and support?
They have a good technical support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. It is easy to maintain as well.
What about the implementation team?
I implemented the product myself.
What other advice do I have?
I recommend Cortex XDR by Palo Alto Networks and rate it an eight out of ten. It is a good solution for the commercial sector as they can work on the cloud. I advise others to refer to user guides for understanding the processes easily.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Cortex XDR by Palo Alto Networks
December 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Solution Engineer at Secure Soft Corporation
An easy-to-use product with an intuitive dashboard that enables users to navigate easily
Pros and Cons
- "The product has an intuitive dashboard."
- "It is a complex solution to implement."
What is our primary use case?
The solution is like a next-level EDR. It can collect information from other solutions to have a global view of the risks and vulnerabilities.
What is most valuable?
The product has an intuitive dashboard. The first time a client interacts with the solution, they do not face any problems. It is easy for the client to navigate through the tool.
What needs improvement?
It is a complex solution to implement.
For how long have I used the solution?
My organization sells the solution.
How are customer service and support?
I did not have any problem with support.
How would you rate customer service and support?
Positive
How was the initial setup?
I believe the implementation is not very easy, but it is not very complex either.
What's my experience with pricing, setup cost, and licensing?
The price of the product is not very economical. It is suitable for clients that have a lot of money to invest.
What other advice do I have?
Customers often ask for proof of concept. People wanting to use the solution should analyze the different tools that can be integrated with the product. At first, clients only consider it an EDR, but later, they might realize that the tool does not have all the capabilities they need. Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Head Of Sales at Cascade Solutions
A stable solution for security with good support
Pros and Cons
- "The tool's use cases are relevant to security."
- "The tool needs to be improved in terms of integration and interface."
What is our primary use case?
The tool's use cases are relevant to security.
What needs improvement?
The tool needs to be improved in terms of integration and interface.
For how long have I used the solution?
I have been working with the solution for five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I would rate the product's scalability a nine out of ten.
How are customer service and support?
The product's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is easy. The solution's deployment took five days to complete.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive. It's pricing is on a yearly-basis.
What other advice do I have?
I would rate the tool a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Senior Security Consultant at a tech services company with 201-500 employees
Automated, with well defined policies, but privacy is a concern
Pros and Cons
- "The most valuable feature is that you can select remote access of any machine for sandboxing."
- "Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
What is our primary use case?
We use this solution specifically in endpoint response, endpoint detection, endpoint sandboxing, and as a firewall.
How has it helped my organization?
The product is mostly automated, and we do not have to make decisions. All the decisions are made by the product itself.
We are not required to create any custom policies.
The policies that are created are well defined in the product itself.
What is most valuable?
The most valuable feature is that you can select remote access of any machine for sandboxing.
Irrespective of whether you have the rights or not, you can still access it from the cloud.
What needs improvement?
I would like to see some sort of attachment scanning included.
Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access.
I want a plugin for email attachment scanning and email body scanning.
For how long have I used the solution?
I have been using this solution for two years.
We are using version seven.
What do I think about the scalability of the solution?
Scalability is not a problem with this solution.
It's a cloud setup. You can scale in and you can scale out as per the cloud.
We have close to 500 users in our company.
How are customer service and technical support?
Technical support is very good, but it can be a problem, especially in the Gulf region.
If you do not take direct support, you have to wait for 72 hours.
Also, direct support is a little bit costly.
Which solution did I use previously and why did I switch?
We used McAfee previously. We switched because the solution is pretty automated. You don't have to manually decide on the policy.
How was the initial setup?
The initial setup is pretty straightforward.
In one hour, you can deploy the entire setup and get started.
After the setup, deployment can take up to three to four days.
We had one admin test the solution and maintain it for us.
What about the implementation team?
We did not use an integrator or vendor team.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay, although direct support can be expensive.
What other advice do I have?
It is a very straightforward product with minimum administer interference, once it is deployed.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior System Administrator at a government with 10,001+ employees
WildFire AI helps detect and prevent threats, but the dashboard should be more intuitive
Pros and Cons
- "WildFire AI is the best option for this product."
- "The dashboard is the area that needs to improve so that we can have the ability to drill down without having to go elsewhere to verify results."
What is our primary use case?
We use Palo Alto Traps in our Windows-based environments. Currently, it only protects our desktops and we use it in conjunction with our Check Point firewall.
How has it helped my organization?
The product is very good, it has caught a lot of exploits that most products would not. The WildFire module is a great AI in detecting and preventing attacks. The only issues that we have are, one the cost, two the dashboard is not very intuitive, even though you can drill down within the dashboard, we usually have to gather information from other sources to determine locations and if its a false positive.
What is most valuable?
WildFire AI is the best option for this product.
What needs improvement?
The dashboard is the area that needs to improve so that we can have the ability to drill down without having to go elsewhere to verify results.
For how long have I used the solution?
We have had this product for two years.
What's my experience with pricing, setup cost, and licensing?
This is an expensive solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sales Engineer at a security firm with 51-200 employees
Reliable with good support, but the installation should be simplified
Pros and Cons
- "Stability is one of the features we like the most."
- "The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
What is our primary use case?
We use this solution to secure endpoints and to have more visibility on what is happening on the endpoints.
We have two customers who are using this solution currently.
What needs improvement?
The installation should be easier and the Palo Alto pre-sales and sales should teams have more information on the product because they don't know what they are selling.
They don't know the features of the products they sell.
For example, Cortex XDR includes Cortex XDR Prevent, Cortex XDR Pro, and Cortex XDR Pro per TB. They don't know the real differences between Cortex XDR Pro and Cortex XDR Pro per TB.
Sometimes, they will tell you about features for one edition that belong to another edition. They don't seem to know what features belong to what edition.
For how long have I used the solution?
I have been working with this solution for one month.
We are familiar with Cortex XDR Prevent and Cortex XDR Pro.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
How are customer service and technical support?
Technical support is okay.
How was the initial setup?
The initial setup is complex. It is not easy to install.
We have been deploying this solution for a month, but we are not finished yet.
We only need one engineer for the deployment and maintenance.
What other advice do I have?
I would recommend this solution to anyone who is interested in using it.
I would rate Cortex XDR a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Information information analyst at Seeton
It's a simple platform that's easy for administrators and users
Pros and Cons
- "Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features."
- "The playbooks could be improved to include more functionalities or actions."
What is most valuable?
Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features.
What needs improvement?
The playbooks could be improved to include more functionalities or actions.
For how long have I used the solution?
I have been using Cortex XDR for a few months.
What do I think about the stability of the solution?
Cortex XDR is highly stable.
What do I think about the scalability of the solution?
Cortex XDR is scalable.
Which solution did I use previously and why did I switch?
We previously used McAfee, but we switched because of our customer. We checked Gartner's to learn about each vendor and solution and consulted with the customer about the features they needed.
How was the initial setup?
Cortex XDR is a cloud-based solution, so the deployment is straightforward. They give you your credentials to access the platform and you change some settings to customize it.
What other advice do I have?
I rate Cortex XDR by Palo Alto nine out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
VMware Carbon Black Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?