No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point Infinity vs Corelight Open NDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in AI-Powered Cybersecurity Platforms
1st
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd)
Check Point Infinity
Ranking in AI-Powered Cybersecurity Platforms
6th
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
38
Ranking in other categories
Advanced Threat Protection (ATP) (9th), AI Security (5th), AI Observability (5th)
Corelight Open NDR
Ranking in AI-Powered Cybersecurity Platforms
12th
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
7
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (19th), Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (7th)
 

Mindshare comparison

As of October 2026, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 12.1%, up from 12.0% compared to the previous year. The mindshare of Check Point Infinity is 4.8%, up from 0.7% compared to the previous year. The mindshare of Corelight Open NDR is 2.1%, down from 5.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks12.1%
Check Point Infinity4.8%
Corelight Open NDR2.1%
Other81.0%
AI-Powered Cybersecurity Platforms
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
RL
TI at a security firm with 51-200 employees
Helps prevent advanced threats and reduce incident response times through unified security policies
The best feature Check Point Infinity offers for me is threat prevention, which is effective at blocking malware, ransomware, and phishing, as well as preventing zero-day attacks before they reach users or systems. For our team, the threat prevention in Check Point Infinity works by layering multiple defenses that stop attacks before they reach users or systems, and the most effective feature for us is the specific SandBlast Zero-Day Prevention, which uses advanced sandboxing and threat emulation to detonate suspicious files in a safe environment. Check Point Infinity has impacted my organization positively, as I have seen a reduction in security incidents and response times, with threats that used to slip through different point solutions now being blocked automatically thanks to the unified prevention layers.
reviewer2834367 - PeerSpot reviewer
Growth And Strategy Lead at a computer software company with 51-200 employees
Network visibility has transformed how we detect nation state threats and protect critical industry
Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale. However, I think with a lot of the artificial intelligence that they are building in, it is getting a lot easier to query in the platform. I would definitely encourage them to continue down that path where anybody can hop into the platform and start running queries, whether it is a simple instruction like I want this, and an artificial intelligence process can actually build the query and do it. I think that would be super powerful. Cyber skill sets are in high demand, and there is a huge backlog in cyber talent. We cannot fill all the positions we need. The easier we can make these cyber systems for people to pick up and be effective on, I think is really key. Explainability of data is hyper important. In the past few artificial intelligence related updates we have gotten from Corelight, that has been one of the first questions our team has asked every time or that I have asked: show me what the model is doing, show me how it came to this analysis. Within Investigator platform, they are able to walk through and see exactly what data the artificial intelligence pulled from where and why it did what it did as far as making its suggestions. They have definitely built their system with artificial intelligence in mind up front, and having that openness as one of the key features of any of their artificial intelligence and machine learning processes in the platform is important. The issue with black boxes is obviously hallucinations from artificial intelligence and just not being able to trace to ground truth. When we are talking about these cyber incidents and being able to do forensics, you need to be able to pinpoint and tie everything together, and black boxes really obscure that and prevent you from doing so. Corelight has done a really good job of making sure that everything is explainable and everything is mapped when it comes to leveraging any of their artificial intelligence features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
"Technical support is the best in class, in my opinion, because they have invested heavily in research and development."
"If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
"After installing this solution, it identified, blocked, and provided the complete attack chain, which was very helpful."
"Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
"Has great threat detection capabilities."
"Being a cloud solution it is very flexible in serving internal and external connections and a broad range of devices."
"The live terminal is probably the best thing ever. It gives you the access to get straight onto any machine."
"Clients can manage everything - the data center firewall, the perimeter firewall, and the cloud, etc., from one single consolidated management that makes everything more visible and transparent from one place."
"One of the valuable aspects of Check Point Infinity is that I can use one unified portal for the administration of all these tools."
"We have seen a faster response time and reduced effort from the network and security engineers while going through logs."
"Check Point Infinity has enabled us to manage cloud, network, and endpoint security from a single platform, which has reduced complexity and improved response times."
"It is a scalable product."
"The Infinity portal combines all Check Point solutions in one place, including the endpoint, SASE, and the SMP."
"Check Point Infinity has positively impacted my organization by streamlining security prevention and strengthening our overall posture."
"Powerful cyber security functionalities track workflows to block all threats that may arise and affect the workflow chain."
"It's easy to create additional dashboards specific to supporting specific tasks."
"Corelight is easy to use."
"Our company has seen massive improvements in cybersecurity position for our clients."
"Technical support seems to be good."
"The most valuable feature is the embedded IDS from Suricata."
"It is easy to deploy and easy to handle."
"Corelight Open NDR has had a positive impact on my company, providing visibility as the Suricata engine can scan huge volumes of traffic, including north-south and east-west, revealing signatures and exposures I was not expecting and enabling me to catch them with Suricata alerts."
"It's an easy way for us to get visibility in a client's environment."
 

Cons

"For Cortex XDR by Palo Alto Networks, if I had to point out improvements, I would say the UI is still somewhat difficult for beginners."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"The GUI could be improved. It's a little bit cumbersome. It could be more user-friendly."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
"I don't like that they have different types of licenses. For example, if users select a license, they think they will have all the platforms they need to improve their network or security. But after some time, Palo Alto Networks changed their licensing, and some of the features that, for example, were free at the beginning now have a cost. I think the integration can be improved. For example, a lot of tools are just integrated through APIs."
"I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."
"They are charging for Network Traffic Analyzer (NTA) services, so if the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better."
"The tool's technical support lags."
"Some aspects of the reporting in Check Point may take time to learn and become comfortable with."
"I think that the pricing for the Check Point products should be reconsidered, as we found it to be quite expensive to purchase and to maintain."
"One area where Check Point Infinity could improve is in the reporting and analytics customization."
"The customer support is average because I need to create different things in the portal to create a ticket."
"In terms of pricing, I find Check Point Infinity to be an expensive product. In fact, we are evaluating even the spam filter for emails from Check Point, but it was prohibitively costly, so we dropped it and are using Microsoft Defender."
"One point that led to the nine rating was an incident about two months ago where our inbound and outbound mail were going to quarantine and we could not do anything."
"Check Point Infinity is not compatible with Windows 8."
"The solution’s architecture is complex and difficult to understand. There are multiple machines and VMs."
"In the next release, building a graphical user interface would be helpful."
"It's an expensive solution and the price could be reduced."
"Machine learning could be a good improvement, but it's very costly."
"They can enhance the interface of the product. They can make it more interactive and also easier to use for feature access."
"Corelight hasn’t added features in a long time."
"Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale."
 

Pricing and Cost Advice

"The cost depends on your chosen license type, like Pro or other licenses."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"The price was fine."
"It is "expensive" and flexible."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"This is an expensive solution."
"It has a yearly renewal."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
"Choosing the correct set of licenses is essential because, without the additional software blade licenses, the Check Point gateways are just a stateful firewall."
"The flexibility in pricing is advantageous, and being a special partner allows for negotiating special rates based on the project requirements."
"The solution's price is quite high, and the licensing model requires extra licenses for various features like SD-WAN."
"The pricing of Check Point Infinity could be better. There is a license needed to use the solution and we pay annually."
"The product has good pricing considering the features and a global approach."
"Check Point should provide an enterprise-wide license where the organization should be provided free hand of using any license or services for an agreed period of time (EULA)."
"When it comes to price, the paramount consideration is the strength of the security. If the security measures provided by the product, such as Check Point Infinity, are robust and meet our requirements, price becomes a secondary concern."
"It's a yearly fee and depends on what you are looking for."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Manufacturing Company
13%
Security Firm
13%
Financial Services Firm
11%
Educational Organization
8%
Financial Services Firm
12%
Government
9%
Real Estate/Law Firm
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise10
Large Enterprise10
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Check Point Infinity?
Check Point Infinity could be improved with more intuitive documentation.
What is your primary use case for Check Point Infinity?
Check Point Infinity is used primarily for consolidating security across networks, including cloud and on-premise, an...
What advice do you have for others considering Check Point Infinity?
Check Point Infinity offers easy management, a centralized security tool, and excellent pricing. The review rating fo...
What is your experience regarding pricing and costs for Corelight?
I have a fortunate experience with pricing, setup costs, and licensing of Corelight Open NDR, as being a principal ar...
What needs improvement with Corelight?
Corelight Open NDR does not need any improvements or additional features in the next releases. The product is excelle...
What is your primary use case for Corelight?
I have been using Corelight Open NDR solution for approximately three years. I leverage the Suricata engine heavily f...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
R80, Infinity
Corelight Open NDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Edel AG
CarrefourEdnonGrand Canyon EducationSektorCERTTietoevryVolkswagen Financial Services
Find out what your peers are saying about Check Point Infinity vs. Corelight Open NDR and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.