Palo Alto Networks delivers a complete solution that helps Tier-1 through Tier-3 analysts and SOC managers to optimize the entire incident life cycle while auto documenting and journaling all the evidence. More than 100+ integrations enable security orchestration workflows for incident management and other critical security operation tasks.


| Product | Mindshare (%) |
|---|---|
| Palo Alto Networks Cortex XSOAR | 8.6% |
| Microsoft Sentinel | 11.2% |
| Splunk SOAR | 7.6% |
| Other | 72.6% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Security Orchestration Automation and Response (SOAR) | Apr 16, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Apr 16, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Microsoft Sentinel | Apr 16, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Splunk SOAR | Apr 16, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Torq | Apr 16, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| IBM Security QRadar | 4.0 | 5.7% | 90% | 217 interviewsAdd to research |
| Microsoft Sentinel | 4.1 | 11.2% | 93% | 108 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 19 |
| Midsize Enterprise | 6 |
| Large Enterprise | 23 |
| Company Size | Count |
|---|---|
| Small Business | 315 |
| Midsize Enterprise | 172 |
| Large Enterprise | 650 |
Palo Alto Networks Cortex XSOAR is a piece of Security Orchestration, Automation, and Response software that redefines what it means for a program to orchestrate security in an automated manner. It is a next-generation solution that offers all of the features of dozens of siloed security operations center tools in one place. Cortex XSOAR combines case management, automation, real-time collaboration, and threat intelligence management to create a platform that can handle all aspects of system security. Teams that make use of Cortex XSOAR can expect to cut the number of issues that they will have to deal with by 75%. At the same time, the speed at which they resolve those issues that slip through will rise by 90%.
Cortex XSOAR ensures that all of the IT and security tools that you employ function as a unified system. It does this by employing hundreds of integrations that allow you to run a wide variety of programs at once without ever worrying about them interfering with each other. These integrations are limited only by your imagination. They can be used immediately as they are, if that is what you need. However, they can also be customized according to the requirements of your system. This approach provides you with the maximum levels of both flexibility and utility.
The model that this platform uses is based on a machine learning algorithm. The level of automation allows you to provide more than an unchanging and inflexible blanket of coverage. Cortex XSOAR takes all of the data that it gathers and uses it to expand its protective capabilities. This creates recommendations that you can use to create a threat playbook that can be deployed uniformly throughout your organization.
Benefits of Palo Alto Networks Cortex XSOAR
Some of Palo Alto Networks Cortex XSOAR’s benefits include:
Reviews from Real Users
Palo Alto Networks Cortex XSOAR’s centralized monitoring interface and automation are two features that help it stand out. This might help explain why one quarter of the Fortune 500 companies choose Palo Alto Networks Cortex XSOAR over the competition.
Peerspot users note the effectiveness of these features. One user wrote, “We were looking for a single pane of glass type of solution that would allow us to physically be in one appliance - be able to work in concert with other servers that we have within our environment. We wanted orchestration and automation. The single pane of glass was the most important part.” Another noted, "The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."
Palo Alto Networks Cortex XSOAR was previously known as Demisto Enterprise, Cortex XSOAR, Demisto.
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
| Author info | Rating | Review Summary |
|---|---|---|
| Enterprise Security Architect V at FirstEnergy | 4.5 | I find Palo Alto Networks Cortex XSOAR a highly customizable and automatable central hub for incident response, despite occasional system slowdowns with high alert volumes. Setup was easy, and it aids metric tracking, though support has time zone challenges. |
| Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees | 4.5 | I value Cortex XSOAR for its security automation, playbooks, and integrations, dramatically improving SOC efficiency. My main concern is the poor UI/UX, and initial setup challenges, though stability and scalability are generally strong. |
| Vice President, Technology at Cache Digitech Pvt Ltd. | 3.0 | As a reseller, I find Palo Alto Networks Cortex XSOAR offers good automation, analytics, and integrations, with great support. However, its high cost limits it to larger companies, and it needs more low-code features. I rate it 6/10. |
| Assistant Security Architect at Cloudnomics | 4.0 | I use Cortex XSOAR for malware incidents, valuing its automation and marketplace for reducing MTTR. Yet, I find playbook creation difficult for junior analysts, despite the product's stability, scalability, and easy integration. |
| Manager at Deloitte | 4.5 | I find XSOAR excellent for automation, compliance, and multi-language scripting, making orchestration easy. Its heavy UI and high licensing costs are major drawbacks, but it delivers significant ROI for mature SOCs. |
| Presale Engineer at Westcon-Comstor | 4.0 | I use Cortex XSOAR as a stable and scalable orchestration automation platform for security events, rating it 8/10. While its versatility and automation are valuable, its complexity and integration requirements mean deployment isn't easy. |
| BDM/Chief Information Officer at Afcor PLC | 4.0 | I find Palo Alto Networks Cortex XSOAR user-friendly, stable, and easy to configure. It needs more AI-centric products, more connectors, and a lower price, though its playbooks are good. I rate it 8/10. |
| Cyber Security Analyst at Altisec Technologies Pvt Ltd | 5.0 | I find Cortex XSOAR excellent for streamlining security and automating complex playbooks. Its vast integration library and scalability are valuable, though Python playbook creation can be tedious. I've experienced great stability and support, rating it 10/10. |