No more typing reviews! Try our Samantha, our new voice AI agent.

Anomali vs CrowdStrike Falcon Insight XDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Anomali
Ranking in Extended Detection and Response (XDR)
8th
Average Rating
8.0
Reviews Sentiment
6.2
Number of Reviews
13
Ranking in other categories
Security Information and Event Management (SIEM) (8th), User Entity Behavior Analytics (UEBA) (5th), Advanced Threat Protection (ATP) (11th), Threat Intelligence Platforms (TIP) (2nd)
CrowdStrike Falcon Insight XDR
Ranking in Extended Detection and Response (XDR)
34th
Average Rating
9.6
Reviews Sentiment
7.0
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
TarunKumar11 - PeerSpot reviewer
Global Leadership Council at a tech company with 10,001+ employees
Strategic threat intelligence has improved detection speed and consistently reduces analyst workload
Anomali can be improved in various aspects. Its AI-driven automation can further advance, and AI-powered investigation summaries can improve. User experience could be enhanced through simplification of workflows. Better board-level cyber risk dashboards could provide easier visualization. Additionally, Anomali could work on simplifying the pricing structure. Although it excels in threat intelligence aggregation and operationalization, stronger GenAI capability, improved executive reporting, and a more intuitive workflow for analysts would further increase SOC efficiency and add more business value. Regarding Anomali's AI capabilities, governance and security are quite good. Anomali has incorporated AI and machine learning primarily to improve correlation and prioritization. These capabilities are valuable but could be more mature. The platform could achieve better threat correlation, prioritization, more anomaly detection, and allow AI to accelerate intelligence analysis while further improving quality and relevance. The accuracy and reliability of Anomali's AI output are fairly reasonable and good. The AI engine works well, but this capability could be improved. Better threat correlation with threat actors, certain indicators of compromise, malware, and campaigns is possible. Threat prioritization could increase, and alert noise could be reduced through further de-duplication. While reasonable, this is not the best available, and other products possibly have more AI maturity, such as Recorded Future and CrowdStrike Falcon.
reviewer2894520 - PeerSpot reviewer
Senior Manager at a consultancy with 11-50 employees
XDR telemetry has transformed threat hunting and now simplifies correlation across tools
The improvements I have observed in my process for detecting and investigating sophisticated attacks since adopting CrowdStrike Falcon Insight XDR is the quality of the telemetry that it collects. It collects all the right information you need to be able to detect threats and conduct threat hunting. The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR ensures that I am actually getting value out of my full security tooling stack, bringing everything together into one spot. Every product has its own blind spots, but when you bring them all together, you get a better picture of what is going on. The detection capabilities of CrowdStrike Falcon Insight XDR have influenced my approach to identifying and addressing sophisticated threats by focusing on the correlation aspects and utilizing multiple data sources to detect those threats rather than having individual detections that utilize only one source. CrowdStrike Falcon Insight XDR has definitely reduced my mean time to detect and mean time to respond, though I could not give exact figures. The impact that CrowdStrike Falcon Insight XDR has had on alert volume and analyst investigation time is definitely reducing the volume of alerts by correlating data sources. Anytime you do that, you are speeding up or reducing the amount of work an analyst does and speeding up the time for them to do things. My experience with CrowdStrike Falcon Insight XDR's behavioral detections and Indicators of Attack has been good overall. I think it is hitting many of the points I have already mentioned in terms of correlating those data sources, making it easier to detect things and easier to investigate them. These detection methods integrate into my current security operations workflows by generally forming the centerpiece. I am actually a consultant, so I do not have a specific workflow myself, but I work with multiple clients, many of them using CrowdStrike Falcon Insight XDR, and it brings in a lot of information and stitches it all together.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable aspect of Cortex XDR by Palo Alto Networks for me is its integration with AI detection, where we get to know the behavioral detection based on users, traffic patterns, and different services that we consume."
"Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
"Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
"The integrations are out-of-the-box, as are the playbooks."
"The protection offered by this product is good, as is the endpoint reporting."
"If you are looking to deploy a security solution as a whole, this is a good option."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"Implementing Cortex XDR by Palo Alto Networks has had a significant impact on my security analyst workload because it becomes much easier."
"Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR, or threat intelligence platform—operates in multiple shifts."
"Anomali has positively impacted my organization and my clients by helping them improve threat visibility, accelerate incident response, and make better use of their resources."
"The most valuable aspect of Anomali is the threat modeling capability."
"I have seen a return on investment with Anomali, as it improves analyst investigation time, enhances threat visibility, and supports fast incident responses."
"I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
"With Anomali, we benefit by obtaining threat information prior to incidents, making our threat hunts proactive and having incident response plans ready, which saves almost 40% of the time from the traditional model."
"The feature I have found most valuable is credential monitoring. This feature is easy and quick."
"Anomali positively impacts our organization, notably improving our vulnerability management program under reducing attack surface management."
"CrowdStrike Falcon Insight XDR has positively impacted my organization by allowing us to understand behaviors and how our customers are suffering attacks, enabling us to anticipate those breaches."
"CrowdStrike Falcon Insight XDR gives us the overhead in terms of resources to make the most of what we have, and anytime I can free up myself to help my end users is a win."
"Without a doubt, CrowdStrike Falcon Insight XDR is making their lives easier."
 

Cons

"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"The price could be a little lower."
"It tends to do 99.9% of things. The only thing I'd like is single sign-on authentication into their cloud platform so that my users can be properly authenticated against it."
"Enhancing UI simplicity and playbook flexibility are areas that could benefit from more low-code automation options for smoother integrations."
"It'll help if customization was easier."
"The solution should offer more dashboards and they should be better customized."
"The main issue I could point out is the offline agents and the way that it is missing."
"There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
"Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side."
"One more improvement I would mention is regarding compromised credential monitoring. Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials."
"An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsistent, as any company can use any tags for their reporting."
"Support in the past has been top-notch, but recent trends indicate that it has taken a back seat, as we often don't get answers for days."
"Anomali can be improved by expanding its capability to capture a broader range of threats because it currently has limitations and may not catch everything occurring in the world, especially from the dark web."
"My experience with Anomali's customer support has not gone so well for us."
"A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
"Less code in integration would be nice when building blocks."
"My experience with pricing, setup cost, and licensing could be better."
"CrowdStrike Falcon Insight XDR can be improved by expanding the number of built-in integrations."
 

Pricing and Cost Advice

"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"I don't recall what the cost was, but it wasn't really that expensive."
"Cortex XDR’s pricing is very reasonable."
"It's about $55 per license on a yearly basis."
"The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"It is "expensive" and flexible."
"This is an expensive solution."
"When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price."
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Comms Service Provider
11%
Outsourcing Company
11%
Financial Services Firm
10%
Construction Company
9%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise14
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Anomali Enterprise?
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted w...
What needs improvement with Anomali ThreatStream?
I can mention one point regarding improvements for Anomali, which is more enhanced reporting flexibility. The reporti...
What is your primary use case for Anomali ThreatStream?
I was using Anomali primarily for threat intelligence operations, security monitoring, and threat detection initiativ...
What is your experience regarding pricing and costs for CrowdStrike Falcon Insight XDR?
My experience with pricing, setup cost, and licensing for CrowdStrike Falcon Insight XDR is that it is very manageabl...
What needs improvement with CrowdStrike Falcon Insight XDR?
CrowdStrike Falcon Insight XDR can be improved with a little more positive press about how good you are.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Match, Lens, ThreatStream, STAXX, Anomali Security Analytics
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Bank of England, First Energy, UBISOFT, Bank of Hope, Blackhawk Network
Information Not Available
Find out what your peers are saying about Anomali vs. CrowdStrike Falcon Insight XDR and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.