Try our new research platform with insights from 80,000+ expert users

Cybereason Endpoint Detection & Response vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
1.0
Cybereason EDR boosts network visibility, reduces threat response time by 50%, and offers ROI in 12-24 months.
Sentiment score
6.9
Cortex XSOAR enhances ROI by automating tasks, requiring mature SOC processes for effective use and reduced false positives.
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
 

Customer Service

Sentiment score
5.0
Cybereason's customer service is competent and knowledgeable, though escalations can cause delays, especially without partnership status.
Sentiment score
6.4
Palo Alto Networks Cortex XSOAR support is responsive and skilled, though experiences vary with occasional delays and access issues.
Nine is great actually since we have people available when we ask, and they know what they are talking about.
if you're a partner with them, they provide fairly good support through a concept called invest support.
The technical support provided by Palo Alto Networks Cortex XSOAR is good.
Their support has been better than Anomali's and they are more responsive.
 

Scalability Issues

Sentiment score
6.2
<p>Cybereason Endpoint Detection &amp; Response is highly scalable, effectively supporting large organizations with seamless expansion and flexible adaptation.</p>
Sentiment score
7.3
Palo Alto Networks Cortex XSOAR is praised for scalability and integration, handling enterprise demands with careful large deployment planning.
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
 

Stability Issues

Sentiment score
5.5
Cybereason EDR is reliable with occasional upgrade issues, but improves system speed, and support resolves performance concerns.
Sentiment score
7.5
Palo Alto Networks Cortex XSOAR is stable and reliable, with occasional bugs and performance issues, especially in cloud environments.
We inform Cybereason about any issues, and they work on a new solution, either with an update or a custom fix in anticipation of the next update.
 

Room For Improvement

Cybereason needs better support, simpler deployment, and enhanced features, including automation, dashboard design, and compatibility improvements.
Cortex XSOAR requires improved documentation, expanded IoT support, enhanced features, and better pricing for streamlined integration and user experience.
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Deployment is not easy, requiring significant tuning and building of integrations over weeks.
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play.
 

Setup Cost

Cybereason offers a competitively priced, comprehensive EDR solution with potential cost benefits for experienced users in enterprises.
Palo Alto Networks Cortex XSOAR is costly but offers valuable integration and features, appealing to medium and large enterprises.
For customers, it is zero versus $20 million, which is why they have to make a decision.
 

Valuable Features

Cybereason EDR offers real-time threat visibility, automatic isolation, and extensive threat-hunting for efficient endpoint management and minimal false positives.
Cortex XSOAR excels in integration, automation, and customization, enhancing security operations with efficient orchestration and high user satisfaction.
What I find most valuable is the clarity of the platform.
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
 

Categories and Ranking

Cybereason Endpoint Detecti...
Average Rating
7.8
Reviews Sentiment
5.6
Number of Reviews
22
Ranking in other categories
Endpoint Protection Platform (EPP) (41st), Endpoint Detection and Response (EDR) (33rd)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
48
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cybereason Endpoint Detection & Response is designed for Endpoint Detection and Response (EDR) and holds a mindshare of 1.1%, up 1.0% compared to last year.
Palo Alto Networks Cortex XSOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 9.7% mindshare, down 12.2% since last year.
Endpoint Detection and Response (EDR) Market Share Distribution
ProductMarket Share (%)
Cybereason Endpoint Detection & Response1.1%
CrowdStrike Falcon11.4%
Microsoft Defender for Endpoint10.1%
Other77.4%
Endpoint Detection and Response (EDR)
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR9.7%
Microsoft Sentinel16.3%
AWS Security Hub8.3%
Other65.7%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Ivan Burke - PeerSpot reviewer
Offers useful threat hunting and response capabilities but struggles to justify cost for smaller deployments
I mostly work with incident response, so I work with a bunch of them interchangeably, but mostly with the EDR components; I also get involved with some of the XDR components, especially for the cloud. Regarding analysis features, such as deep behavioral detection, I do use it sometimes; I usually don't use the automated version of it, as I prefer threat hunting directly, depending on if the season is available. I know some of them have pretty good analytics engines, but I tend to do the threat hunting on my own. I manage incident response for a bunch of companies, so some of them have Cybereason Endpoint Detection & Response integrated into Sentinel, some into Fortinet, and others into various tools. When considering cost-effectiveness, their pricing structure works such that if you're a large organization with more than a thousand endpoints to deploy to, then Cybereason Endpoint Detection & Response is worthwhile. But for anything less than 300, it's too expensive; obviously, the more you buy, the better the price, making it cheaper for you. Cybereason Endpoint Detection & Response best fits enterprise-level businesses such as huge corporations; however, we are in the process of removing it from many of our endpoint clients because it's not really showing enough value for them at the moment. We're trying to see how we can improve it with some of our clients, but at the moment, it's struggling compared to other EDR solutions that we have deployed. On a scale of one to ten, I rate Cybereason Endpoint Detection & Response a six.
DayaramGoyal - PeerSpot reviewer
Offers automation but requires enhancements for intuitive configuration
Palo Alto Networks Cortex XSOAR is a good product with enhanced and efficient playbooks, as demonstrated during our use case simulations. We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs. The analytics feature in Palo Alto Networks Cortex XSOAR is impressive. The solution is quite exhaustive regarding integrations, with many pre-integrations available, especially for market-leading products. There might be challenges with make-in-India products, as they tend not to build the necessary connectors. This depends on whether you are selling to enterprises or other customers. For government customers, you might encounter many Indian products, such as firewalls, which could pose integration challenges unless you have open APIs. However, for market-leading products, there are ready-made integrations available.
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
867,445 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
8%
Comms Service Provider
7%
Financial Services Firm
15%
Computer Software Company
11%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise4
Large Enterprise13
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise24
 

Questions from the Community

What is your experience regarding pricing and costs for Cybereason Endpoint Detection & Response?
Comparison with other products showed it be cheaper than some larger competitors. Set up cost for us were cheaper as we already had users experienced with the product in other business units. Initi...
What is your primary use case for Cybereason Endpoint Detection & Response?
My main use case for Cybereason Endpoint Detection &amp; Response is mostly for incident response.
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
 

Also Known As

Cybereason EDR, Cybereason Deep Detect & Respond
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Lockheed Martin, Spark Capital, DocuSign, Softbank Capital
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about CrowdStrike, SentinelOne, Microsoft and others in Endpoint Detection and Response (EDR). Updated: January 2025.
867,445 professionals have used our research since 2012.