Cortex XDR is used for endpoint detection and response. This is software placed into endpoints and work in this cloud. In cloud has the analytics, login, prevention models, et cetera.
Lead Security Engineer at ESKA
Scalable with excellent protection features and is very user-friendly
Pros and Cons
- "The solution doesn't need a high level of technical training."
- "Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well."
What is our primary use case?
What is most valuable?
If a company uses Palo Alto and supports Cortex XDR for endpoint protection it is very well protected. Palo Alto is the best security solution in the market. It's very advanced and its protection is extremely reliable.
The solution doesn't need a high level of technical training. The solution is very usable and doesn't take a lot of personnel.
The product is very scalable.
The stability is very good.
What needs improvement?
For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible.
Cortex does not offer an on-premises solution. However, some customers would prefer not to be on the cloud. It would be ideal if it could offer something on-prem as well.
For how long have I used the solution?
I've been working with this security solution for ten years or so and Palo Alto Networks for two years.
Buyer's Guide
Cortex XDR by Palo Alto Networks
November 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution has been very stable and very reliable. There are no bugs or glitches. It doesn't crash or freeze. It's one of the best on the market.
What do I think about the scalability of the solution?
The solution is very scalable. It works well for companies that are quite sizeable. If an organization needs to expand it, it can do so easily.
We have about 50 to 55 users on the solution.
How are customer service and support?
I personally handle technical questions for those working with Palo Alto.
Support of Palo Alto is English, however, I work in this local technical solution, local technical and I'm working with customers with a warranty.
I've found technical support from Palo Alto to be very good. We're local and we can assist as well, however, Palo Alto is capable of handling any size of issue and they are quite helpful.
How was the initial setup?
I am not directly handling the installation. My client is.
You do need a team of people on this solution that understand the cloud and the solution itself if you have a large, complex environment. If you have a robust security team, it's good. However, if you don't have the resources, it's not an ideal product.
That said, if your company requires a small, simple setup, one person may be enough. It really depends on the size.
What about the implementation team?
My client is actually handling the installation. I often field questions from them, however, I don't participate in the installation directly.
What's my experience with pricing, setup cost, and licensing?
For basic needs, the solution isn't very expensive. However, as you grow more complex in your needs, the more you use, the more costly it can get.
The licensing is typically for one year. There's a one-time installation. If you would like to continue with the service, you can continue. There's no need to install and reinstall.
What other advice do I have?
Cortex XDR is a threat analytics security manager that allows users to see what threats are going to endpoints. It's a very high-security solution.
The next step up from Cortex XDR is Cortex XSOAR. XSOAR is an automated threat solution. It's a security solution from Palo Alto.
I'd recommend the solution to others. I'd rate it at a nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Senior Information Security Architect at a tech services company with 201-500 employees
Great machine learning capabilities, a strong cloud platform and good overall features
Pros and Cons
- "It collects and caches and the knowledge of machine learning from different customers to take to the cloud. It makes it better to use for everybody. It allows for quick learning and updates and can, therefore, offer zero-day malware security. This sharing of metadata helps make the solution very safe."
- "The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements."
What is our primary use case?
I primarily use this solution for my clients. I don't use the solution myself.
What is most valuable?
I can call the tweak responses or other items that the customer doesn't like very easily due to the fact that this solution is on the cloud
It collects and caches and the knowledge of machine learning from different customers to take to the cloud. It makes it better to use for everybody. It allows for quick learning and updates and can, therefore, offer zero-day malware security. This sharing of metadata helps make the solution very safe.
Even the firewalls have their signatures. It takes from different resources and takes note of everything.
The exploits and malware technology are really good.
What needs improvement?
It's my understanding that this solution is at end-of-life.
It's hard to use as a product. It's not easy or straightforward. Especially when I deal with a government sector or other sensitive industries. They do not accept that it's so easy to share metadata outside their organization. They prefer on-prem even if it is not as powerful due to the fact that they perceive it as being more secure.
The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements.
The deployment is pretty hard. Competitors like Trend Micro or Symantec have features on their console that make them easier to use. This solution does not offer items that would increase its usability.
Before I moved to technical sales, I handled implementation, and I remember it being very difficult. They need to improve this aspect.
The solution provides a lot of false positives. The average amount of false positives you get is 5%. It would be great if this could be lowered.
For how long have I used the solution?
I've been using the solution for a year and a half.
What do I think about the stability of the solution?
Security people usually think it's a very powerful solution. However, government teams always worry about the security of the cloud and always need to send approvals. Since this solution is not a normal endpoint, it can be a bit tricky for compliance purposes.
At the same time, it does its job. It's very good at vulnerability management.
That said, it is really not really flexible to make deployments on certain platforms. It's really complicated. Sometimes the solution falls off.
How are customer service and technical support?
We've contacted technical support in the past and they are very good. They are usually quite capable of closing the issue for us. They're also great if we're working out a new configuration or doing a completely new implementation. We're satisfied with their level of service.
How was the initial setup?
The initial setup is not straightforward. It's not that it's complex per se. It's difficult.
The IVR needs to be reached on the outside. You need to make it to the server and that's connected to the database that communicates with the agent properly. You have to push the agents and put the sensors inside the network.
What about the implementation team?
We're an integrator; we implement this solution for our clients.
What other advice do I have?
We have a partnership with Palo Alto. I'm a consultant, I'm pre-sales as a technical sales engineer. I try to show the value of any product for the customer. I don't actually use the solution myself.
The solution does not have an on-premises option. It's only available on the cloud.
For XDR new users just need to make sure they have the right policies in place. The solution does offer pre-configured policies. Organizations will want to make sure it is actually fitting them in the places where they will be working best. It's important as well that they don't make it a default selection. Users need to make sure that it's really configured and whitelisted and everything fits the organization.
I'd rate the solution eight out of ten. I'd rate it higher, however, the deployment process is poor even though the features are decent. Competitors like Carbon Black have much easier deployments.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Cortex XDR by Palo Alto Networks
November 2024
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
CIO/CTO at a manufacturing company with 501-1,000 employees
Good GUI, however lacks features overall and tends to eat memory
Pros and Cons
- "They have a new GUI which is just fantastic."
- "There's an overall lack of features."
What is our primary use case?
We primarily use the solution for our endpoint server and endpoint protection.
What is most valuable?
There aren't many features we find valuable on the solution.
They have a new GUI which is just fantastic.
What needs improvement?
The solution eats memory of the computer, unlike anything I've ever seen. It eats more memory than Chrome.
I have a lot of users that are eating my memory each hour every day and it's causing us problems. We have to go and buy more memory for each computer. When you have a lot of computers like we do, is not a very good situation.
Some of the computers are only using 4 GB of memory, so if you put aside the differences, most only have some Chrome, some internet, and Office and that's it. And yet, the memory is getting eaten.
If someone catches something like malware, or something else, I want to know if the file was spread to other machines and what the target was. I want to be able to get ahead of the spread. This solution doesn't do enough to protect us against these types of vulnerabilities or to give us much information about the spread. The tool really does need some more reverse engineering features.
There's an overall lack of features.
The initial setup could use improvement. Currently, I must go to each machine and deploy everything manually. We are in 2020, not in 1980. It seems like such a dated way of doing large deployments.
For how long have I used the solution?
I've been using the solution for a year and a half.
What do I think about the stability of the solution?
When I was experimenting with stability early on, I did run into issues when testing the solution in the sandbox.
Eventually, it catches one of the executive files and if you go to the management section of the solution and you release this file, it takes seven or eight tries to do it. You need to keep trying, again and again, using the same procedures to release the file for usage. That was in the beginning and we still have this issue, even though they made a new GUI for management. It's still not resolved.
What do I think about the scalability of the solution?
We have several hundred users.
I had some issues initially in the sandbox when I was testing scalability.
How are customer service and technical support?
I have reached out to technical support in the past. I find dealing with them is like talking to a wall. They aren't terrible, however, you don't really get any guidance. They ask over and over to get us to send them dump files and we do over and over. After all of the back and forth, nothing is really resolved to our satisfaction. You're paying for their services, and you don't get the level of service you would expect. It's a pain point.
How was the initial setup?
The initial setup was not complex. It was very straightforward.
The deployment did take a lot of time due to the fact that we had seven hundred computers.
What other advice do I have?
We simply use the solution as a customer.
I would not recommend the solution. I'd advise other companies to rather go with Palo Alto's firewall as a better option. I've already advised others not to touch it. It's not worth it at all to even consider using it.
I'd rate the solution six out of ten. Their new GUI is very nice, however, as a professional service, it's lacking in a lot of areas.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solution Engineer at Secure Soft Corporation
An easy-to-use product with an intuitive dashboard that enables users to navigate easily
Pros and Cons
- "The product has an intuitive dashboard."
- "It is a complex solution to implement."
What is our primary use case?
The solution is like a next-level EDR. It can collect information from other solutions to have a global view of the risks and vulnerabilities.
What is most valuable?
The product has an intuitive dashboard. The first time a client interacts with the solution, they do not face any problems. It is easy for the client to navigate through the tool.
What needs improvement?
It is a complex solution to implement.
For how long have I used the solution?
My organization sells the solution.
How are customer service and support?
I did not have any problem with support.
How would you rate customer service and support?
Positive
How was the initial setup?
I believe the implementation is not very easy, but it is not very complex either.
What's my experience with pricing, setup cost, and licensing?
The price of the product is not very economical. It is suitable for clients that have a lot of money to invest.
What other advice do I have?
Customers often ask for proof of concept. People wanting to use the solution should analyze the different tools that can be integrated with the product. At first, clients only consider it an EDR, but later, they might realize that the tool does not have all the capabilities they need. Overall, I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Head Of Sales at Cascade Solutions
A stable solution for security with good support
Pros and Cons
- "The tool's use cases are relevant to security."
- "The tool needs to be improved in terms of integration and interface."
What is our primary use case?
The tool's use cases are relevant to security.
What needs improvement?
The tool needs to be improved in terms of integration and interface.
For how long have I used the solution?
I have been working with the solution for five years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I would rate the product's scalability a nine out of ten.
How are customer service and support?
The product's technical support is good.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's setup is easy. The solution's deployment took five days to complete.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive. It's pricing is on a yearly-basis.
What other advice do I have?
I would rate the tool a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Senior Security Consultant at a tech services company with 201-500 employees
Automated, with well defined policies, but privacy is a concern
Pros and Cons
- "The most valuable feature is that you can select remote access of any machine for sandboxing."
- "Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access."
What is our primary use case?
We use this solution specifically in endpoint response, endpoint detection, endpoint sandboxing, and as a firewall.
How has it helped my organization?
The product is mostly automated, and we do not have to make decisions. All the decisions are made by the product itself.
We are not required to create any custom policies.
The policies that are created are well defined in the product itself.
What is most valuable?
The most valuable feature is that you can select remote access of any machine for sandboxing.
Irrespective of whether you have the rights or not, you can still access it from the cloud.
What needs improvement?
I would like to see some sort of attachment scanning included.
Data privacy is a matter of concern. You have to be careful with data privacy, it can be sensitive and Cortex can have most of your access.
I want a plugin for email attachment scanning and email body scanning.
For how long have I used the solution?
I have been using this solution for two years.
We are using version seven.
What do I think about the scalability of the solution?
Scalability is not a problem with this solution.
It's a cloud setup. You can scale in and you can scale out as per the cloud.
We have close to 500 users in our company.
How are customer service and technical support?
Technical support is very good, but it can be a problem, especially in the Gulf region.
If you do not take direct support, you have to wait for 72 hours.
Also, direct support is a little bit costly.
Which solution did I use previously and why did I switch?
We used McAfee previously. We switched because the solution is pretty automated. You don't have to manually decide on the policy.
How was the initial setup?
The initial setup is pretty straightforward.
In one hour, you can deploy the entire setup and get started.
After the setup, deployment can take up to three to four days.
We had one admin test the solution and maintain it for us.
What about the implementation team?
We did not use an integrator or vendor team.
What's my experience with pricing, setup cost, and licensing?
The pricing is okay, although direct support can be expensive.
What other advice do I have?
It is a very straightforward product with minimum administer interference, once it is deployed.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
A stable and scalable solution with an easy setup and out-of-the-box playbooks and integration
Pros and Cons
- "The integrations are out-of-the-box, as are the playbooks."
- "The solution should offer more dashboards and they should be better customized."
What is our primary use case?
I have deployed some customized playbooks and modified ones which are out-of-the-box with more integration with SIEM solutions such as ArcSight, QRadar, ADRs and Trend Micro.
What needs improvement?
The solution should offer more dashboards and they should be better customized. The case number of items should be addressed.
I have found the interface of Azure to be more simple and customizable than that of the solution.
For how long have I used the solution?
I have worked on Cortex XDR by Palo Alto Networks with my customers for a number of weeks.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
The scalability is fine.
We have plans to increase the usage.
How was the initial setup?
The initial setup was simple.
The deployment took no more than two hours.
What's my experience with pricing, setup cost, and licensing?
So far, I have made use of the free license which is offered. Once it ended, I was able to buy a license based on the number of users or divisions. The license varies with the number of users or applications involved.
If one wishes to work with another team or large number of users at a future point, he must purchase a license for them.
Which other solutions did I evaluate?
The interface of Azure is more simple and customizable than Cortex XDR by Palo Alto Networks.
What other advice do I have?
I have found the solution to be very easy in respect of the integration and configurable. The integrations are out-of-the-box, as are the playbooks.
The solution is deployed solely on-premises on a single server.
As of now, there are six users making use of the solution.
My advice is that the on-premises environments for the product's use should be increased.
I rate Cortex XDR by Palo Alto Networks as an eight out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sales Engineer at a security firm with 51-200 employees
Reliable with good support, but the installation should be simplified
Pros and Cons
- "Stability is one of the features we like the most."
- "The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
What is our primary use case?
We use this solution to secure endpoints and to have more visibility on what is happening on the endpoints.
We have two customers who are using this solution currently.
What needs improvement?
The installation should be easier and the Palo Alto pre-sales and sales should teams have more information on the product because they don't know what they are selling.
They don't know the features of the products they sell.
For example, Cortex XDR includes Cortex XDR Prevent, Cortex XDR Pro, and Cortex XDR Pro per TB. They don't know the real differences between Cortex XDR Pro and Cortex XDR Pro per TB.
Sometimes, they will tell you about features for one edition that belong to another edition. They don't seem to know what features belong to what edition.
For how long have I used the solution?
I have been working with this solution for one month.
We are familiar with Cortex XDR Prevent and Cortex XDR Pro.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
How are customer service and technical support?
Technical support is okay.
How was the initial setup?
The initial setup is complex. It is not easy to install.
We have been deploying this solution for a month, but we are not finished yet.
We only need one engineer for the deployment and maintenance.
What other advice do I have?
I would recommend this solution to anyone who is interested in using it.
I would rate Cortex XDR a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
VMware Carbon Black Endpoint
Check Point Harmony Endpoint
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?