My main use cases include workload protection, endpoint and perimeter protection of the environment, data center, and also the cloud.
Cortex XDR by Palo Alto Networks provides advanced threat detection with AI-driven endpoint protection and seamless integration, ensuring multi-layered security and automatic threat response.



| Product | Mindshare (%) |
|---|---|
| Cortex XDR by Palo Alto Networks | 4.8% |
| SentinelOne Singularity Endpoint | 6.4% |
| Wazuh | 5.3% |
| Other | 83.5% |
| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 20 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 3152 |
| Midsize Enterprise | 1293 |
| Large Enterprise | 2177 |
Cortex XDR is designed to safeguard endpoints against malware and suspicious activities. It offers advanced threat detection and response capabilities using behavioral analysis, AI, and machine learning. It seamlessly integrates with security infrastructures, providing endpoint security, firewall integration, and enhanced visibility in both cloud-based and on-premises environments.
What are the key features of Cortex XDR?Organizations in diverse sectors deploy Cortex XDR to protect against malware, leveraging its advanced threat detection capabilities. Its integration with existing security infrastructures appeals to those seeking comprehensive protection in both cloud and on-premises environments, providing enhanced visibility and threat intelligence.
Cortex XDR by Palo Alto Networks was previously known as Cyvera, Cortex XDR, Palo Alto Networks Traps.
CBI Health Group, University Honda, VakifBank
| Author info | Rating | Review Summary |
|---|---|---|
| Senior Process Expert at A.P. Moller - Maersk | 4.5 | I value Cortex XDR's AI detection and 360-degree security view. Initial false positives and feature gaps were resolved, making it stable, scalable, and well-supported. It now offers complete visibility and reduced operational overhead, justifying its cost. |
| Final Year Student at Gitam University | 4.5 | I found Cortex to be the best endpoint detection tool, extensively using its automation and playbooks for incident response and threat intelligence. While highly effective and stable, I suggest improvements like UI simplicity, faster sync, and better third-party integrations. |
| Cybersecurity Engineer at Gigabit Technologies Pvt Ltd | 5.0 | Cortex XDR significantly improved my organization's endpoint visibility, threat detection, and incident response, especially with its behavioral analysis and process tree. It's stable, scalable, and offers good ROI, though I'd like simpler integrations and a more intuitive analyst experience. |
| Soc Analyst at Softcell Technologies Limited | 5.0 | I find Cortex XDR excellent for EDR, behavior analysis, and SOAR integration, offering great stability and scalability. Setup is easy and it's cost-effective, but policy complexity and false positives need attention and fine-tuning. |
| Cyber Security Engineer at Olacabs | 4.5 | I find Cortex XDR highly effective; its intuitive UI simplifies threat detection, investigation, and real-time threat blocking, saving me significant time. However, its cost might be prohibitive for smaller companies. |
| Network Security Engineer at Cyberwell Solution | 5.0 | I find Cortex XDR excellent for securing acquired clinics, preventing incidents effectively with its simple management, stability, and scalability. I value its strong ROI and excellent support, though I believe the end-device application viewing feature should be free. |
| Cyber Engineering Manager at a tech vendor with 10,001+ employees | 4.0 | Cortex XDR significantly improved my organization's network visibility and reduced threat dwell time through excellent telemetry and easy threat hunting. While powerful, its cost is high, and CrowdStrike offers better overall performance, though I still recommend it for its benefits. |
| Head of data centers at a non-profit with 10,001+ employees | 4.0 | I find Cortex XDR highly effective for AI-driven threat blocking and investigation, significantly reducing our risk and outperforming previous solutions. Its performance and support are excellent, but I consider its financial cost to be very high. |
| Business Development Manager For Palo Alto Networks at a tech services company with 1,001-5,000 employees | 4.0 | I rate Cortex XDR highly for its zero-day prevention and ecosystem. However, the 200-license minimum and missing MSSP model hinder adoption for smaller companies, despite its stability and scalability. Customer support needs improvement. |
| Principle Cloud Architect at a tech services company with 11-50 employees | 4.0 | I found Cortex XDR excellent for replacing traditional antivirus, significantly reducing staff, and improving threat detection. While expensive, it offers strong integration within the Palo Alto ecosystem, delivering great value. I hope for more non-Palo integrations and improved container security. |

My main use cases include workload protection, endpoint and perimeter protection of the environment, data center, and also the cloud.
The most valuable aspect of Cortex XDR by Palo Alto Networks for me is its integration with AI detection, where we get to know the behavioral detection based on users, traffic patterns, and different services that we consume. It's more about user and behavior analysis with upfront detection rules and automation that we can integrate with for orchestration purposes.
It's effective. We have seen multiple occasions where we were notified with the detection rule, and the SOC team engaged with us, and we took the remediation action as and when it was highlighted.
The positive impacts I see from Cortex XDR by Palo Alto Networks include a complete 360-degree view of our security posture altogether, being a uniform platform where we are ingesting logs from multiple resources. We have AI detection for different levels of user behaviors, and we integrate with the firewall engines and WAF, along with the EDRs and XDR, so that we have a complete overall security view and have gained much more confidence in it.
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items.
The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there.
They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now.
Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Almost two to three years now.
Cortex XDR by Palo Alto Networks is very much stable. The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
It's scalable for our workload.
It's always good. We have a dedicated customer success representative, and we get to address all our tickets with them.
For tech support, I would give close to eight or nine. Most of the cases are getting resolved well within the SLAs. There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
Positive
We've moved to Palo Alto firewalls and VMware firewalls, so we are not using Cisco anymore.
It was straightforward since we did the deployment from scratch. Rather than fixing the firewall into the design, we did the design by handling the high-level design and documentation from scratch. It was smooth with no major issues.
It was a mix. For the POCs, we were involved, but for the actual production workload, we did consult with the CSP managers to see if we were doing things right.
Cortex XDR by Palo Alto Networks is one of the top-tier products. When you get engaged for a long-term contract, they do provide some discounts and negotiation on that. It's open for negotiation based on the business need. I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together. That's the price that you have to pay for using such a tool.
It's a direct purchase.
We did a couple of POCs with different vendors. SonicWall, we had FortiGate and Fortinet, and also we did some POC on cloud-native firewalls and other options.
Overall, Cortex XDR by Palo Alto Networks covers all our business needs with scalability and not much operational overhead. There is much less operational overhead and complete visibility in the environment. I would rate this product an 8.5 out of 10.

I have been using Cortex for my internship at Palo Alto, where I have used Cortex XDR and Snort tools to detect endpoint and endpoint detection. I have also used similar tools like threat intelligence management to analyze the alerts and suspicious activities. Cortex is the best tool for endpoint detection.
I have used Cortex in a specific scenario where there are certain types of threat intelligence management features. I have used it to verify hashes or domains to identify malicious activity. I also use Cortex XSOAR and Xnor to trigger playbooks that automate and gather endpoint logs, block malicious processes, and update incident tickets, showcasing end-to-end processes with automation in investigation and reducing the analysis workflow.
I have used Cortex for my internship and afterward in certain projects where I'm working with my college. In those projects, I have been using Cortex for automation through playbooks and using intelligence to prioritize the incidents. I have also practiced to understand the incident lifecycle management from detection to containment.
Cortex is deployed in my organization as part of a hybrid cloud setup, where Cortex XDR and Xnor components are primarily cloud-hosted by Palo Alto Networks. This arrangement allows for easier management and updates while integrating sensitive data sources with our on-premises systems for security and compliance reasons. The hybrid approach balances the scalability and availability of the cloud while maintaining control and data security with on-premises infrastructure.
The best features Cortex offers in my experience include its capability for detection and investigation, along with several types of threat intelligence management. It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds. In playbooks, automation handles responding actions such as isolating endpoints or enriching IOCs, along with reducing mean time to detect and mean time to respond. I have used this for my SOC operations environment, discussing it with my college.
Automation and playbooks have helped me significantly. If there is a threat, detecting it used to be a lengthy process. Now, with the advancement in technology, Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context. These automations collect relevant indicators such as hashes, IP addresses, or domains efficiently and can detect and block malicious attacks with firewalls. It is very useful for eliminating workload of human errors, speeding responses for next-generation operations. Playbooks are customizable with dynamic analysis that align with organizational policies.
I think Cortex is the best tool, but there are a few points that could be added to improve it. For instance, enhancing UI simplicity and playbook flexibility are areas that could benefit from more low-code automation options for smoother integrations. AI-based alert prioritization features could enhance efficiency for SOC units.
Cortex is a very good and accurate tool, and if some other tools could be integrated, such as third-party tools including Splunk, ServiceNow, and Microsoft, it would significantly enhance usability. Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly. APIs should be efficient, coupled with simpler low-code notebooks for customizing smart AI-based incident prioritization systems.
While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor. Although the synchronization is fast, it could be enhanced to generate new alerts more quickly. There could also be more granular role-based access control for better permission management, along with built-in playbook templates for common incident types such as phishing, allowing users to deploy automations more swiftly.
I haven't used any tools before Cortex during my internship. This was my first experience with an endpoint detection tool, and I find it to be the best tool I have encountered.
In my experience, I have not faced any issues with Cortex; it functions seamlessly. There are no major downtimes reported, and the system remains reliable and efficient, with only minor sync delays under high data loads.
Cortex remains fast and responsive, even with increasing data and alerts. Although there is a slight delay during peak load, the overall performance is stable and efficient.
Cortex can handle data loads effectively, showing its scalability.
As an intern, I manage my tasks independently, utilizing the extensive resources available online to learn how to use Cortex without needing customer support.
Positive
I haven't used any tools before Cortex during my internship. This was my first experience with an endpoint detection tool, and I find it to be the best tool I have encountered.
Cortex is the only tool provided to me throughout my internship, and I believe it is an excellent choice for endpoint detection and automation. I have enjoyed a great user experience with it, making it a standout tool.
Before using Cortex, it's essential to research its features and capabilities. This knowledge aids users in becoming proficient. I advise new users to start small with playbooks, focus on data quality for XDRs, and plan integrations carefully for improved response speed and efficiency.
I believe Cortex is a great tool that everyone working in cybersecurity should try. Those who use it will fall in love with it due to its automation capabilities and the numerous helpful features it offers. I would rate this product a nine out of ten.

My main use case for Cortex XDR by Palo Alto Networks is endpoint security and threat detection. I use it to monitor endpoint activity, investigate suspicious behavior, and respond to potential security incidents. For example, in my daily work, I would receive Cortex XDR by Palo Alto Networks alerts for suspicious processes or malware activity. I investigate the affected endpoint and process tree, check the associated user or network activity, and then take action accordingly, such as isolating the endpoint or terminating the malicious process if required.
I have one scenario I find particularly useful: investigating suspicious PowerShell activity. I would start with the Cortex XDR by Palo Alto Networks alert, review the process tree and command-line arguments, identify the parent process and the affected user or endpoint, and correlate the activities with the network connection and other related alerts.
Cortex XDR by Palo Alto Networks has helped improve our endpoint visibility and incident investigation capabilities. The biggest impact has been having centralized visibility into endpoint activity and better context around security alerts, which makes it easier to investigate suspicious behavior. We have also seen improvement in incident response time and alert investigation because the process tree and behavioral detection and correlated activity provide more context without requiring multiple separate tools.
I would describe the improvement mainly in terms of investigation efficiency rather than a formally measured percentage. For example, an investigation that previously required checking multiple consoles and manually correlating endpoint activity could often be narrowed down significantly faster using Cortex XDR by Palo Alto Networks' incident correlation and process tree visibility. In our typical suspicious PowerShell incident, I can quickly identify the affected endpoint, user, parent-child processes, command line, and network activity from the same investigation view.
Before implementing Cortex XDR by Palo Alto Networks, the main challenges were limited endpoint visibility, a high volume of security alerts, and the need to manually correlate information from different security tools. Investigating suspicious activity could take more time because analysts had to piece together the user, process, file, and network activity. After deploying Cortex XDR by Palo Alto Networks, we have better centralized endpoint visibility and more contextualized alerts.
The biggest outcome has been faster and more effective incident response. Cortex XDR by Palo Alto Networks has given us better endpoint visibility and richer investigation context, allowing us to identify suspicious activity, understand the attack path, and contain potential threats much faster than before.
Cortex XDR by Palo Alto Networks has made our security operations more centralized and investigation-driven. Instead of manually correlating information from multiple sources, the team can use behavioral detection, incident correlation, and process tree analysis to identify the root cause more quickly. For leadership purposes, Cortex XDR by Palo Alto Networks helps us communicate security value through clearer visibility into incidents, affected endpoints, and detection trends. We can demonstrate not just how many alerts were generated, but how quickly threats were investigated and contained.
We started seeing meaningful value within the first few weeks of deployment, once the endpoints were onboarded and the initial policy and detection were tuned. We began getting better visibility into endpoint activity and suspicious behavior. The benefit became more noticeable over the following one to three months as we tuned alerts, reduced false positives, and became more familiar with the investigation and response workflows.
The main features that stand out the most to me in Cortex XDR by Palo Alto Networks are advanced endpoint detection and response, behavior-based threat detection, process tree and investigation, incident correlation, endpoint isolation and response, threat intelligence integration, and XDR capabilities. These represent the main and best features of Cortex XDR by Palo Alto Networks.
Behavior-based threat detection and process tree investigation are two features I find particularly useful when investigating endpoint incidents. Behavior-based threat detection looks for suspicious patterns of activity rather than relying only on known malware signatures. Process tree investigation helps me understand the complete chain of execution. For example, I can trace an activity such as Outlook, Word, PowerShell, suspicious script, and network connection. In my daily work, these features help me quickly understand the root cause of an alert, reduce false positives, and determine the appropriate response.
I view Cortex XDR by Palo Alto Networks' AI capabilities positively from a governance and security perspective. The main value is using AI to help correlate large amounts of security telemetry, identify suspicious behavior, prioritize alerts, and support investigations without relying entirely on manual analysis. From a governance standpoint, I would still want clear visibility into why an AI-driven detection and recommendation was generated, with appropriate access controls including auditability and human approval for high-impact response actions.
One strength is that the AI can connect seemingly disparate activity and provide valuable correlation.
Cortex XDR by Palo Alto Networks is a strong platform, but there are a few areas where I think it could be improved, such as simpler investigation workflow, alert tuning, reporting and dashboards, automation, and third-party integration. Broader and simpler integration with different SIEM, ITSM, and security tools would make it easier to fit Cortex XDR by Palo Alto Networks into heterogeneous environments.
One area where the workflow could be smoother is SIEM and ITSM integration. For example, when a Cortex XDR by Palo Alto Networks incident is confirmed, it would be useful to automatically create a ServiceNow or Jira ticket with the incident summary, including affected endpoints, user indicators, process tree, severity, and recommended response actions. Similarly, for SIEM integration, having more standardized and customizable event mappings would make it easier to correlate Cortex XDR by Palo Alto Networks data with firewall, identity, and network logs.
I would rate it an 8 rather than a 10 mainly because there is still room to improve the user experience around complex investigations, including alert tuning and third-party integration. Some workflows can require additional configuration and manual effort, especially in environments with multiple security tools.
I have covered all the important areas. If I had to add one more important point, it would be simplifying the overall analyst experience. Cortex XDR by Palo Alto Networks provides extensive data and capability, but making investigations, alert tuning, reporting, and integrations more intuitive would help analysts work faster.
I have been working with Cortex XDR by Palo Alto Networks for around two years, primarily focusing on endpoint security, threat detection, investigation, and incident response.
Cortex XDR by Palo Alto Networks has been generally stable in our experience. We have not encountered any major stability issues, and the platform has performed reliably for endpoint monitoring, detection, and incident response.
Cortex XDR by Palo Alto Networks has scaled well with our environment and supports onboarding additional endpoints without major infrastructure changes. It has met our needs as the organization has grown.
Overall, the customer support has been good, and the support team has been responsive and helpful when we need assistance with troubleshooting, configuration, or technical issues.
The customer support has been responsive and helpful, especially for troubleshooting technical issues. On that basis, I would rate the customer support 9 out of 10.
Before Cortex XDR by Palo Alto Networks, we used a traditional endpoint security EDR solution that provided basic malware detection and endpoint monitoring. We decided to move to Cortex XDR by Palo Alto Networks because we wanted stronger behavior-based detection, deeper process-level visibility, better incident correlation, and integrated response capabilities. The main reason for switching was to reduce manual investigation and give the security team more context around suspicious activity. Cortex XDR by Palo Alto Networks' ability to correlate endpoint events and provide a detailed process tree made it easier to identify the root cause and respond to threats more quickly.
I would say we have seen a positive return on investment primarily through time savings and improved analyst efficiency rather than headcount reduction. For example, before Cortex XDR by Palo Alto Networks, investigating a suspicious endpoint event could require manually correlating information from multiple tools and take 30 to 60 minutes or more. With Cortex XDR by Palo Alto Networks' incident correlation, behavioral detection, and process tree visibility, similar initial triage can often be completed in roughly 10 to 20 minutes, depending on the incident.
My experience with pricing and licensing was generally positive. Although the overall cost depends on the number of endpoints, selected capabilities, and licensing term, the initial setup cost was mainly related to deployment and endpoint onboarding, policy configuration, and integration, rather than significant infrastructure costs because Cortex XDR by Palo Alto Networks is cloud-based.
The combination of strong endpoint detection and behavioral analytics and integrated investigation and response capabilities convinced me to choose Cortex XDR by Palo Alto Networks over other solutions. Cortex XDR by Palo Alto Networks provides detailed process-level visibility and correlates related activities. The centralized management, threat intelligence, incident correlation, and endpoint response capabilities were also important factors. Overall, it offered a good balance of detection depth, investigation capabilities, and operational efficiency compared with the alternatives we had evaluated.
We evaluated solutions such as Microsoft Defender for Endpoint, CrowdStrike Falcon, and SentinelOne before selecting Cortex XDR by Palo Alto Networks.
In my organization, we actually use a hybrid deployment, combining cloud and on-premises solution.
We use Palo Alto Networks' hosted cloud infrastructure for Cortex XDR by Palo Alto Networks, so we don't directly manage or select the underlying cloud provider.
I would recommend Cortex XDR by Palo Alto Networks for organizations looking for strong endpoint visibility, behavioral threat detection, and faster incident response. Before deployment, I would recommend clearly defining use cases, tuning policies, and planning integration with existing security tools.
I would rate Cortex XDR by Palo Alto Networks an 8 out of 10.

Cortex XDR by Palo Alto Networks is used for endpoint detection and response, detection, behavior analysis, and analysis. Whenever we get a hit from a ransomware attack or malicious PowerShell attack, or if traditional theft or lateral movement has happened in our organization, we have created multiple use cases for Cortex XDR by Palo Alto Networks.
The behavior capability is very good for Cortex XDR by Palo Alto Networks because we have integrated it with SOAR technology. Whenever we get an alert on the EDR, it directly hits the SOAR technology and we get the alerts within a very short span of seconds. The behavior analysis and integration part is good, and we can integrate any other products.
Cortex XDR by Palo Alto Networks is used for endpoint detection and response, detection, behavior analysis, and analysis. Whenever we get a hit from a ransomware attack or malicious PowerShell attack, or if traditional theft or lateral movement has happened in our organization, we have created multiple use cases for Cortex XDR by Palo Alto Networks.
The behavior capability is very good for Cortex XDR by Palo Alto Networks because we have integrated it with SOAR technology. Whenever we get an alert on the EDR, it directly hits the SOAR technology and we get the alerts within a very short span of seconds. The behavior analysis and integration part is good, and we can integrate any other products.
Improvement-wise, there is a large number of features, and as per user type, such as read-only access or admin access, we have to give the exact features to the user. Report customization could be more flexible.
Fine-tuning the detection policy requires experience because the policy is very complex in Cortex XDR by Palo Alto Networks, and we get high false positive alerts. Fine-tuning the alerts and reducing the false positive alerts is an important improvement.
Policy-wise, it is very complex, and fine-tuning is very important. If we create any custom role in the environment, we have to regularly review the incident policy and update agent versions.
We have been using this solution for six months.
Stability-wise, it is good. I did not hear about any issues in terms of stability. Stability is ten out of ten with no issues there. Cortex XDR by Palo Alto Networks can be trusted completely.
You can scale for an organization with thousands of endpoints. It is a cloud-managed deployment management tool, which is very straightforward. We have two thousand to three thousand endpoints, and since it is cloud-based, it is very easy to deploy. Even at the L1 level, I can deploy that endpoint or do the integration and admin part in Cortex XDR by Palo Alto Networks.
Technical support-wise, it is good at a rating of nine point five.
Before Cortex XDR by Palo Alto Networks, I actually used two to three EDR products, including Defender, SentinelOne, and Symantec EDR. Cortex XDR by Palo Alto Networks is very much known as compared to those because we have integrated it with Palo Alto SOAR technology. Since they are from the same vendor, the integration path is very easy for the EDR and Cortex XDR by Palo Alto Networks and SOAR technology.
It is very easy to set up. The admin team can handle it, and integration-wise, it is very straightforward. We just have to install the agent to the endpoint, and whenever we connect to the network, we usually get the hostname to the management console.
Onboarding-wise is very easy. Deployment typically takes one to two weeks to install everything, depending on customer requirements and the number of endpoints required. As an MSSP provider, we usually estimate one to two weeks for deployment.
The cost is medium cost-efficient. It is not costlier and not very cheap. Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
The setup cost is medium cost-efficient. It is not costlier and not very cheap. Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Symantec EDR is an alternate solution being considered.
We have approximately twenty people managing the implementation. If you are implementing Cortex XDR by Palo Alto Networks and Palo Alto SOAR in your organization, you have to prevent and establish the policies because policy-wise, it is very complex. Then you have to fine-tune the alerts in your environment because whenever we create a custom rule in the environment, we have to fine-tune the alerts. We also have to regularly review the incidents whenever they hit and update the agent for each and every agent because it is used in the investigation timeline for root cause analysis. This solution was given a review rating of ten out of ten.

Our use case for Cortex XDR by Palo Alto Networks is for SIEM and XDR. We install the agents in every endpoint and we monitor those endpoints using our SIEM.
The best features of Cortex XDR by Palo Alto Networks, which I have been using for almost a year, include the very nice operating system and user interface that is so user-friendly, making it very beginner-friendly. You can learn it in less than a week, covering almost all the queries and everything. You can understand the alert very simply. It makes investigation easier and faster, which is the main highlight.
I assess the effectiveness of the AI-driven endpoint security in Cortex XDR by Palo Alto Networks and I know that we only know the risks which are found before. We don't know the risks which are coming in the future. The AI-based detection and BIOC rule detection may help in the future for detecting new threats, which will be helpful for the company.
Cortex XDR by Palo Alto Networks helps a lot with blocking sophisticated threats in real-time because we don't have to care much about the threats which are prioritized by ourselves. If we are only getting the detection and XDR detects it, it means we have to take further action. If we set the priority to block or prevent the action, it will automatically do it. This helps to save our time and allows us to do our further investigation after that.
How much faster it has become to detect and respond to threats depends on the device and defense actions, averaging around 30 minutes.
I have experienced a reduction in alert triage since integrating Cortex XDR by Palo Alto Networks because you can configure the rules and fine-tune them according to the alerts we get. This will be very helpful to prevent false positives. It is very easy to fine-tune in XDR and will take around 15 to 20 minutes if you understand the concept. This can actually prevent the flooding of alerts and will be helpful for triaging the most prioritized alerts.
Implementing Cortex XDR by Palo Alto Networks has had a significant impact on my security analyst workload because it becomes much easier. If you are installing something like an antivirus, it cannot actually prevent us from accessing the endpoint through our computer. Cortex XDR actually helps to access the computer very easily in a short time. The tool is actually really fast and connects very quickly if you want to access the system. It detects and prevents according to the BIOC rule very well, and we get the alert as well. Then we can do the further investigation using that alert. The UI is very simple, and you can connect and check whatever you want in another device. In our company, we mostly depend on XDR.
Cortex XDR by Palo Alto Networks saves me a lot of time because when we get the alert in some other tools, we used to check the alerts using XDR. It only takes a simple time to check the endpoint and determine what activities are going on with XDR. You don't have to get the user's laptop or approach the user at all. You can actually do it from your device very easily. This actually saves a massive amount of time per day.
Last week, the UI of Cortex XDR by Palo Alto Networks actually changed, so I am learning the new UI. I didn't use the UI much, so I'm not aware of the new UI yet. But I think they updated almost all the misconfigurations and everything, making it more easy to use and more beginner-friendly. I don't have any suggestions for improvement as it is already the best.
I have been using Cortex XDR by Palo Alto Networks for the past eight months.
I rate the stability of Cortex XDR by Palo Alto Networks at 8.
For scalability, I confidently rate it a 10.
I haven't contacted the XDR team yet for technical support. It is actually the work of the Endpoint Security team, which is another department. I work in SOC, so the Endpoint Security team contacts the XDR team and connects with them to fix issues. In my case, I have faced issues with XDR two or three times, and they are fixed in around 5 to 10 minutes. I think we can rate this an 8 out of 10.
When I compare Cortex XDR by Palo Alto Networks with other solutions or vendors, I have tried configuring Wazuh(Not an XDR but can be used for endpoint security) agent and found that the UI of other agents feels much harder. In this case, Cortex XDR feels simpler, more normal, and more straightforward as an application UI. Other device solutions' UI feels more old and outdated. It feels more outdated and a bit hard. In this case, it is simpler and much easier to use.
I am not actually aware of how Cortex XDR by Palo Alto Networks is deployed, but we usually install the agents from our IT team. When we get the laptop itself, the IT team installs the agent on each endpoint and it is linked to our ticketing system. We get tickets in our ticketing system using the simple SOAR.
The admin access of Cortex XDR by Palo Alto Networks is with the security team only. There are around many employees in our organization, and for each endpoint, we have installed the XDR. In our cloud instances, everything, we installed the XDR agents. Cortex XDR by Palo Alto Networks is mainly used by us, the security team, mainly around (confidential) N number of people.
Cortex XDR by Palo Alto Networks does require maintenance, but it is mostly done by us itself because of the fine-tuning. The platform security actually maintains Cortex XDR by Palo Alto Networks and they contact the XDR people and do the monthly maintenance.
We are deploying Cortex XDR by Palo Alto Networks on every device, actually. Every device includes Mac, Windows, and Linux.
I would recommend Cortex XDR by Palo Alto Networks to other users, especially if the user has a big MNC or big company. If he is using a smaller company, he can depend on some other tools because Cortex XDR by Palo Alto Networks is a bit expensive. I have given this review a rating of 9.

Our main use case for Cortex XDR by Palo Alto Networks is to manage most of the clinics in the healthcare sector because we acquire a lot of clinics in Ontario and throughout Canada. When we acquire our clinics, we have to enter user devices into our network. At that time, we install Cortex XDR by Palo Alto Networks in their devices to determine if any malicious activities are running on their devices. We have to be 100% sure before we connect their devices into our network. That is why we are using Cortex XDR by Palo Alto Networks to avoid any incidents in our network.
The main function of Cortex XDR by Palo Alto Networks is to prevent any malicious activities that occur on end devices. Beyond that, sometimes I have to add an exception. For example, sometimes our developers team develops some of the healthcare sector applications. At that time, Cortex XDR by Palo Alto Networks behavior analysis detects it as malicious because those applications sometimes acquire user privileges. At that time we have to whitelist those hash files or sometimes the path. Those are uses that I employ for my day-to-day work.
Cortex XDR by Palo Alto Networks offers simplicity and is easy to manage through the GUI.
If you want to add whitelisting to avoid any false positive scenarios with Cortex XDR by Palo Alto Networks, we can easily right-click and add the whitelist for those hash files or perform any whitelisting. It is quite simple operationally.
I can say that Cortex XDR by Palo Alto Networks is doing a very good job because we are acquiring so many clinics, and some of the clinics actually run without any XDR application. In those scenarios, we have to install Cortex XDR by Palo Alto Networks and sometimes we figure out that some malicious applications have been running on those devices. Because of that, we have been able to identify those applications and clean their devices to keep our environment safe.
In that case, I can say that Cortex XDR by Palo Alto Networks has helped me communicate security value or risk reduction to leadership and executives because most of the time we show our dashboard to our top management. Sometimes our SOC team extracts reports showing how many incidents have occurred during the past month. We have different kinds of reports and dashboards to show our management.
I saw one improvement needed for Cortex XDR by Palo Alto Networks. I feel that it should not be a licensed activity because a feature should allow us to see applications running on end devices. However, Cortex XDR by Palo Alto Networks provides it under license for that feature. I feel that it should be added as a free feature because it is more of a concern about applications.
I have been using Cortex XDR by Palo Alto Networks for around two years now.
Cortex XDR by Palo Alto Networks is cautiously stable.
Most of the time we put end devices on auto-update, so there is nothing to worry about. It is automatically updated.
We have not faced any issues with the scalability of Cortex XDR by Palo Alto Networks so far.
Customer support for Cortex XDR by Palo Alto Networks is excellent. I have opened a couple of TAC cases. Most TAC cases are enrolled and resolved within a couple of hours. The support team is quite responsive and quite effective.
I am not sure which solution our current company was using before Cortex XDR by Palo Alto Networks. I have no idea about whether my company evaluated other options before choosing Cortex XDR by Palo Alto Networks.
When I joined this company, Cortex XDR by Palo Alto Networks was already deployed. I do not have any idea about what challenges they were facing before they deployed Cortex XDR by Palo Alto Networks. I do not have any idea about how long it took my team to start seeing meaningful value from Cortex XDR by Palo Alto Networks after deployment, because it was deployed before I joined this company.
Our SOC team has a monitoring team for Cortex XDR by Palo Alto Networks detection. They are the team who monitor the system. Once they monitor and identify any issue, they contact our team. Then we determine if we need to add any whitelisting or handle any false positive action, and we respond accordingly.
I can highlight that we have not faced any security incidents with Cortex XDR by Palo Alto Networks. Our environment is quite dynamic. Even though our environment is dynamic, we have not faced any security incident with Cortex XDR by Palo Alto Networks until now.
I can say that on the employee side, with Cortex XDR by Palo Alto Networks, we need only fewer employees. In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good. We do not need a huge staff to manage 8,000 devices.
The decision for Cortex XDR by Palo Alto Networks pricing, setup cost, and licensing was made by our top management, not from our side. We make a decision for technical feasibility and the security side. We recommend the device to them, and then the pricing decision is taken by our top management.
We had some review about whether we were going to move to a different XDR platform for Cortex XDR by Palo Alto Networks, but in that scenario, my recommendation was to stay with the same XDR because we have not had any issues with Cortex XDR by Palo Alto Networks. Why would we change without any issues with Cortex XDR by Palo Alto Networks?
I mentioned which improvements were needed for Cortex XDR by Palo Alto Networks, and I have nothing further to add at this time.
I can say that compared to other products, Cortex XDR by Palo Alto Networks is quite easy and effective because I have used a couple of different XDR solutions such as SentinelOne.
We do not know about the cloud provider for Cortex XDR by Palo Alto Networks. It is provided by Palo Alto Networks. We do not have any information about it, and we cannot see which cloud provider is used from their back-end side. We just get the console. We do not have any back-end access activity. We do not know which cloud provider is used for hosting the Cortex XDR by Palo Alto Networks console.
Our SOC team has a monitoring team for Cortex XDR by Palo Alto Networks detection. They are the team who monitor the system. Once they monitor and identify any issue, they contact our team. Then we determine if we need to add any whitelisting or handle any false positive action, and we respond accordingly.

Cortex XDR by Palo Alto Networks provides better network visibility for our organization. The telemetry that we look for in EDR was missing from our previous solution. When we ingest and start working with Cortex XDR by Palo Alto Networks, that problem was resolved.
Cortex XDR by Palo Alto Networks definitely helps my security team significantly. The network telemetry and stitching capability is very good, so we don't have to work with multiple alert fatigues. After fine-tuning, the analysis and everything is very impressive.
The best feature of Cortex XDR by Palo Alto Networks is the simplicity of the query languages. You can easily query the languages and everything associated with them. The second thing is the broadness; we can get the telemetry of network devices as well, which is phenomenal, and the ease of using that particular tool is exceptional compared to other tools. Cortex XDR by Palo Alto Networks makes threat hunting activities very easy to use.
The major outcome achieved by my company with Cortex XDR by Palo Alto Networks is that the dwell time of identifying a threat or any incident got minimized. In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy. This helps us reduce alert fatigue and duplicates.
Cortex XDR by Palo Alto Networks definitely helps my company reduce risks and communicate security values. The dwell time got minimized, which is why we are definitely saving ourselves from risks and threats from zero days and many open vulnerabilities.
A potential area of improvement for Cortex XDR by Palo Alto Networks is the cost.
When talking about functionality, they are already working on improvements. They have already completed or added all the details in XIM. If you see XIM, it's a culmination of three products: Cortex XDR by Palo Alto Networks, XDR plus XSOAR. On top of it, they are providing ASM technologies, which is quite good, but the only factor is the cost.
I have been working with Cortex XDR by Palo Alto Networks for more than two years, and my overall experience spans more than four years.
I would rate the stability of Cortex XDR by Palo Alto Networks somewhere around nine, maybe eight, between 8.5 to nine.
The scalability of Cortex XDR by Palo Alto Networks is also an 8 to 9.
For technical support, it depends on the package and license you are taking. Asia Pacific support is not that good, but when you get engineers from the US or Israel, they are better than the others.
Response time depends on the ticket we are raising, and it is good.
Technology-wise, Cortex XDR by Palo Alto Networks is good. Overall performance-wise, if you look at the dwell time and all those details, CrowdStrike excels. SentinelOne is also nearby, but there's a very thin line of difference among all three vendors.
The initial setup for Cortex XDR by Palo Alto Networks is not that difficult, but you need some training and all those elements.
In XDR specifically, it is very easy to install. The reason behind it is that it is using the same agent, which can be pushed via Intune, XSOAR, or XDR. Anything is fine, so nowadays, any XDR or EDR product is very easy to use and implement in the environment. We just have to be very cautious while adding the policies.
We are also handling the reselling part; we are a partner and provide MSSP services with Palo Alto Networks.
Usually, it takes us three months to get live with Cortex XDR by Palo Alto Networks, but it can take three to six months depending on how critical the infrastructure is and how easily they give access.
Based on my experience, a main competitor for Cortex XDR by Palo Alto Networks would be CrowdStrike and SentinelOne.
If I compare the three vendors, I think overall experience-wise, CrowdStrike is the best.
I would definitely recommend Cortex XDR by Palo Alto Networks. I would rate this product 8.5 out of 10.

The most beneficial aspect of Cortex XDR by Palo Alto Networks was when it was first installed in the environment, where there were too many infected and compromised systems. After installing this solution, it identified, blocked, and provided the complete attack chain, which was very helpful. A previous product was not detecting anything, and after installing Cortex XDR by Palo Alto Networks, the experience has been very good.
Positive
There are many clients' use cases for Cortex XDR by Palo Alto Networks, including endpoint protection, the managed service for some resellers who are using it to boost their managed service solutions, and protection reaction.
Cortex XDR by Palo Alto Networks is specifically designed to prevent zero-day attacks. The design of the solution is completely different from other vendors because it is based on the detection of exploit techniques used by attackers. While other vendors are trying to reduce the mean time to respond when an attacker is present, Cortex XDR by Palo Alto Networks aims to prevent zero-day attacks that are becoming more common due to the usage of AI. The reactive approach used by competitors exposes customers to being attacked and exfiltrated more easily. Cortex XDR by Palo Alto Networks can prevent this by design.
Another aspect is that Cortex XDR by Palo Alto Networks is part of an ecosystem of Palo Alto, providing customers with a long-term vision to modify and redesign how security is applied in their company. Palo Alto is probably one of the few vendors that has developed a real platform where the products are not separate identities but part of a unique platform, exchanging data and information natively. Starting from a small piece, a customer can attain the full picture of the Palo Alto product set smoothly.
Cortex XDR by Palo Alto Networks helps to communicate security value or risk reduction to leadership executives primarily due to its effectiveness in working on exploits natively, thereby dramatically reducing the possibility of zero-day attacks. The second risk reduction comes from being part of an ecosystem, which significantly reduces blind spots. By adding modules from Palo Alto's framework, you have the full set of features and coverage for the customer. This also affects operational costs and integration issues between different tools. The massive usage of AI by Palo Alto is something they have been investing in since 2015, which gives them a significant edge. Palo Alto retrieves metadata and information from each customer installation to create a clear picture of what is happening on the internet on a daily basis, processing around 100 petabytes of data each day. This substantial data volume improves the system's ability to proactively respond to attacks.
Cortex XDR by Palo Alto Networks has been designed for a SOC-led service partner environment. If you have this kind of environment, it is the right product for the right place. It is less a next-gen antivirus, as other solutions in the market work more as an evolution or a next-gen antivirus. They require a lot of post-processing by an operator or SOC analyst. In Palo Alto, the solution has been designed to be used by a SOC analyst. Where the SOC analyst is not present, it is having a very good Ferrari without having the wheels.
The negative aspect I see is the economic model used by Palo Alto.
The reason is that the minimum license model is 200 licenses per user, per company, or tenant, and it is not really applicable to Italy, where many companies have less than 200 users. The second area for improvement is the lack of a real MSSP model, which would involve a pay-as-you-go approach on a monthly basis where the reseller buys a certain number of licenses without needing to manage where those licenses are allocated.
The two major areas for improvement are the MSSP model and the economic model. The minimum license of 200 is too high. I understand that Palo Alto is mainly an enterprise-led company and wants to approach the mid-market, but they need to reduce the number of licenses to 50, which could be a good threshold. Below 50, I would not care about these customers, as they are too small and managing them involves more effort than potential gain.
When you have at least 200 users, the price of Cortex XDR by Palo Alto Networks is fine, but if you only have 50 users, you are out of the market.
Since 2021, I have been working with Cortex XDR by Palo Alto Networks.
Cortex XDR by Palo Alto Networks is pretty stable.
The scalability for Cortex XDR by Palo Alto Networks is not an issue; it is super scalable and easy to scale up or out.
In general, I think Palo Alto is experiencing some growing pains in terms of support quality, which is not exceptional at the moment. They have delegated a lot of customer management responsibilities to distributors, so when I sell a Palo Alto solution, I also sell support services from Westcon, not from Palo Alto, to alleviate pressure on their support.
If I were to rate support from zero to ten, I would give it a five because I think it is currently overloaded.
The deployment procedure for Cortex XDR by Palo Alto Networks requires a certain level of know-how. It is not about the installation itself, but the configuration is so powerful that you need to understand the environment where it is installed. If not carefully managed, you may inadvertently block solutions that should be permitted.
Compared to others, I think Cortex XDR by Palo Alto Networks at the moment has the best performances in the market. The MITRE framework states that. The comparable solutions are CrowdStrike, for example, and Cynet, but unfortunately in Italy, Cortex XDR by Palo Alto Networks is not well awarded by the end user or the partners due to the economic model applied by Palo Alto, because Cortex XDR by Palo Alto Networks is mainly an enterprise-led product and not for PMI. PMI are small companies, and as you see in Italy, our market is mainly led by PMI.
When comparing Cortex XDR by Palo Alto Networks to competitors such as CrowdStrike, it seems their model can scale down more easily than Palo Alto's. CrowdStrike has an MSSP program that allows them to cover a broader market than Palo Alto. Regarding Cynet, I do not have a clear picture of their pricing model, but I have heard it is a good product. The EDR and XDR market is very crowded today, so competition is strong.
At the moment, Palo Alto is slightly defocusing on Cortex XDR by Palo Alto Networks because they launched a platform called Cortex XSIAM, which includes the functionalities of Cortex XDR by Palo Alto Networks inside an autonomous SOC, so a SOC with AI-driven intelligence where human intervention is minimized.
Currently, I do not have specific figures, but if you look at reports such as the Verizon Data Breach Investigations Report, you can find that the mean cost of an attack is significant for a company.
The time it takes to start seeing value from the product after deployment is finished is not clear; it depends on the customer and the market they are in. For example, if a customer is in the defense market producing tanks, the risk of an attack is very high, so it is critical to not afford even one attack. However, if a customer is selling screws, the revenue may be high, but the risk of an attack is low, which changes how quickly they recognize value.
What eventually convinces a customer to choose the product is sometimes through a proof of concept; sometimes I find myself in a situation where there is an attack already present.
AWS for me is more a channel for reselling than for deployment, because the cloud solution is provided by Palo Alto. You have an instance on their cloud, which can be installed anywhere, so the main concern is about configuring the cloud instance rather than installing on a specified cloud.
We are partners with Amazon, and we are starting to interact with AWS Marketplace.
Considering the fact that there is an issue with the economic model, I would give the product an eight overall rating.

My clients primarily use Cortex XDR by Palo Alto Networks for the purpose of replacing existing signature-based antivirus on laptops. The last project I completed was about moving away from Symantec antivirus, which is now Broadcom, to a new solution that does not perform signature-based scanning, as that slows down the system whenever scanning occurs. We wanted a next-generation antivirus with integration to the existing Palo Alto firewalls that the client had, leveraging EDR and NDR capabilities for extended detection. We wanted to move from traditional signature-based antivirus to extended detection and response, and consolidate logs, transforming it into an advanced SOC project.
The biggest positive impact I see from Cortex XDR by Palo Alto Networks is a significant reduction in the number of people required to manage it. It stitches the entire lifecycle of an attack; if there is malware or infection on an endpoint, it can track every single activity phase. The tool automatically prioritizes high-risk detections, and it reports anomaly-based behaviors in your network, including zero-day attacks.
The most significant improvement is the performance of your endpoints and servers because, unlike traditional signature-based scanning, there are no delays, which was essential for the financial services institution running high-frequency trading applications on their endpoints.
The major outcomes achieved with Cortex XDR by Palo Alto Networks include improved threat detection, especially for instances where there are no signatures, such as zero-day attacks. We saw improved threat intelligence and contextual risk scores, along with a great GUI that makes managing the solution easy. Regarding ROI, significant savings come from reduced human resources; for example, we went from twenty-four or twenty-five people managing the solution down to about ten, which is a cost reduction and leads to efficient application performance.
For future product updates, I would appreciate integrations with AI-enabled red teaming tools to streamline policy adjustments during penetration testing activities. Additionally, there should be more integrations with non-Palo products to enhance usability without forcing customers to purchase additional Palo Alto products.
Finally, I see room for improvement in container security within Cortex XDR by Palo Alto Networks, particularly regarding Kubernetes orchestration tools.
As a service provider for Palo Alto, I am not using it in the current deployment, and the last time I worked on it was approximately four to five months ago.
Regarding stability, it is good; Palo Alto maintains the system and notifies us about maintenance periods with no disruptions.
Cortex XDR by Palo Alto Networks is easy to scale, providing presence in all locations except China. I am uncertain about current capabilities there, but everywhere else, the cloud scales effectively.
I am very happy with the technical support from Palo Alto; they are the best.
The deployment procedure for Cortex XDR by Palo Alto Networks is straightforward. I push the package from the endpoint manager, install it, and it registers with Cortex XDR by Palo Alto Networks cloud.
It took us about a month and a half to realize meaningful value from Cortex XDR by Palo Alto Networks with seventeen or eighteen thousand workloads primarily in a hybrid multi-cloud environment. The initial onboarding was straightforward, but tuning the policies took time, approximately seven months in total, due to the need for thorough configuration and whitelisting of directories to avoid impacting applications.
It is possible to observe ROI from reduced spending on human resources since we brought the number of people managing the solution down significantly. The investments in the tool shift to human resources, allowing for better ROI. The integration with other solutions also enhances ROI, as it is not only about Cortex XDR by Palo Alto Networks but the overall ecosystem, improving the cumulative result.
Comparing Cortex XDR by Palo Alto Networks to other market solutions, CrowdStrike is the closest alternative that does decent work. There are point solutions such as SentinelOne, but none integrates as thoroughly with other products as Cortex XDR by Palo Alto Networks does.
There is not much of a marketplace; it operates as an agent on a server, and while I can install it on AWS EC2 instances through Systems Manager, it is not a product purchased from AWS.
Cortex XDR by Palo Alto Networks is the solution to choose if you are already a Palo Alto customer because if you are purchasing other parallel services, it allows for reusing existing resources, leading to cost efficiency. You do not want to replicate products you already have, and there should be a strategic roadmap if you plan to purchase Cortex XDR by Palo Alto Networks.
Cortex XDR by Palo Alto Networks changes the way my security team detects, investigates, and responds to threats.
I have not seen anything negative recently with Cortex XDR by Palo Alto Networks; however, when Traps was acquired, false positives were an issue, but that has already been overcome. It is expensive, and the best value is achieved if you are a Palo Alto shop with products such as next-generation firewalls and Prisma. If you are using open-source firewalls or non-Palo solutions, the ability to realize the gains of XDR diminishes as it ends up being only EDR.
Cortex XDR by Palo Alto Networks is not only pricey; it is extremely expensive. I would rate this product an eight out of ten.