No more typing reviews! Try our Samantha, our new voice AI agent.

Corelight Open NDR vs Sophos Central comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in AI-Powered Cybersecurity Platforms
1st
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd)
Corelight Open NDR
Ranking in AI-Powered Cybersecurity Platforms
12th
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
7
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (19th), Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (7th)
Sophos Central
Ranking in AI-Powered Cybersecurity Platforms
9th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
45
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 12.1%, up from 12.0% compared to the previous year. The mindshare of Corelight Open NDR is 2.1%, down from 5.2% compared to the previous year. The mindshare of Sophos Central is 3.0%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks12.1%
Sophos Central3.0%
Corelight Open NDR2.1%
Other82.8%
AI-Powered Cybersecurity Platforms
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2834367 - PeerSpot reviewer
Growth And Strategy Lead at a computer software company with 51-200 employees
Network visibility has transformed how we detect nation state threats and protect critical industry
Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale. However, I think with a lot of the artificial intelligence that they are building in, it is getting a lot easier to query in the platform. I would definitely encourage them to continue down that path where anybody can hop into the platform and start running queries, whether it is a simple instruction like I want this, and an artificial intelligence process can actually build the query and do it. I think that would be super powerful. Cyber skill sets are in high demand, and there is a huge backlog in cyber talent. We cannot fill all the positions we need. The easier we can make these cyber systems for people to pick up and be effective on, I think is really key. Explainability of data is hyper important. In the past few artificial intelligence related updates we have gotten from Corelight, that has been one of the first questions our team has asked every time or that I have asked: show me what the model is doing, show me how it came to this analysis. Within Investigator platform, they are able to walk through and see exactly what data the artificial intelligence pulled from where and why it did what it did as far as making its suggestions. They have definitely built their system with artificial intelligence in mind up front, and having that openness as one of the key features of any of their artificial intelligence and machine learning processes in the platform is important. The issue with black boxes is obviously hallucinations from artificial intelligence and just not being able to trace to ground truth. When we are talking about these cyber incidents and being able to do forensics, you need to be able to pinpoint and tie everything together, and black boxes really obscure that and prevent you from doing so. Corelight has done a really good job of making sure that everything is explainable and everything is mapped when it comes to leveraging any of their artificial intelligence features.
AM
Data Analyst
Centralized protection has secured global endpoints and simplifies daily threat response
I have noticed pain points around installation. Whenever I want to install on devices that are Windows, it is usually a lot of hassle because it is very easy to install on a MacBook. However, when a user is using Windows, installing Sophos Central on Windows is usually a serious undertaking. I think they can improve on that. Additionally, the installation takes a really long time for Sophos Central. While that might be fine if it is doing its job, for Windows it is really quite a lot when you are installing for a particular person. Regarding needed improvements, I would suggest something. Zoho has this ManageEngine feature where users can actually turn off a device from the administrator end. I think if Sophos Central could integrate that in their system, whereby when there is a high alert, I as an IT administrator can easily go there and click on something to turn off the user's work device, I think that would be something I would love to have. That is a feature I would appreciate. I believe if Sophos Central could have something like remote desktop access, similar to Zoho ManageEngine, where when a particular device is attacked, you can toggle off the device from your end or maybe access the device remotely and render it non-functional, that is something I would appreciate seeing on Sophos Central in the future.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like the centralized console and the predictive analysis it does of malware. It is very stable and also scalable."
"Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
"Cortex XDR by Palo Alto Networks's ability to block sophisticated threats in real time is quite good and is on par with SentinelOne's."
"The solution doesn't need a high level of technical training."
"Threat identification and detection are the most valuable features of this solution."
"Palo Alto is the core of the security infrastructure in the environment."
"The solution's most valuable feature is the user interface."
"We can visualize and control the activities in the environment from anywhere."
"It's easy to create additional dashboards specific to supporting specific tasks."
"Our company has seen massive improvements in cybersecurity position for our clients."
"Corelight is easy to use."
"It is easy to deploy and easy to handle."
"Technical support seems to be good."
"Corelight makes much easier the remediation of cyber attacks; instead of facing a chaotic amount of logs, Corelight provides correlated metrics that allow pivoting to find, in seconds, all the data related to an alert, detection, or asset."
"Corelight Open NDR has had a positive impact on my company, providing visibility as the Suricata engine can scan huge volumes of traffic, including north-south and east-west, revealing signatures and exposures I was not expecting and enabling me to catch them with Suricata alerts."
"It's an easy way for us to get visibility in a client's environment."
"The most valuable features of Sophos Central are total threat hunting and detection response."
"One of the significant advantages of Sophos is its affordability compared to other technologies like Check Point and Fortinet."
"The best thing about Sophos Central is how it brings all its security solutions together in one place."
"It is easy to save time using the Sophos Central centralized dashboard. It's definitely easier because you're in one place with all the products."
"The biggest benefit in Sophos Central is the central functionality where I can have my Intercept X integrate the workstations, the servers, and the firewalls I import into Sophos Central."
"Sophos Central is good. It's also free for all those firewalls because, from Sophos Central, we manage the firewalls and push the policies to the firewall."
"The standout feature is its focus on indexing, primarily designed for managing reports and logs from 500 to 1,000 endpoints, including Windows 10 hosts within the network."
"The AI features in Sophos Central help you with investigating any issues, as you can get it to look at the logs for you, and it gives you good feedback on a summary of what it actually has found."
 

Cons

"There's room for improvement with Mac device installations, which can be challenging."
"For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
"Fine-tuning the detection policy requires experience because the policy is very complex in Cortex XDR by Palo Alto Networks, and we get high false positive alerts."
"I would like to see some additional features related to email protection included."
"The dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard."
"The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements."
"They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
"I have run into some detection issues with Cortex XDR. It needs to be better at detection of internal attacks."
"In the next release, building a graphical user interface would be helpful."
"The solution’s architecture is complex and difficult to understand. There are multiple machines and VMs."
"Machine learning could be a good improvement, but it's very costly."
"They can enhance the interface of the product. They can make it more interactive and also easier to use for feature access."
"Corelight hasn’t added features in a long time."
"Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale."
"It's an expensive solution and the price could be reduced."
"I have noticed pain points around installation. Whenever I want to install on devices that are Windows, it is usually a lot of hassle because it is very easy to install on a MacBook."
"As a user, I suggest improving Sophos Central by addressing some error messages we occasionally encounter that we just do not know what they relate to, even when it says it has resolved them."
"The tamper protection password is an area with certain shortcomings where improvements are required."
"Sophos Central must incorporate a diagrammatic graphical user interface for its practices and compliances."
"Having and option for endpoint security on mobile devices, it would be advantageous."
"The phishing campaign training could be more engaging with real-life scenarios."
"The product needs to improve monitoring since it gives false positives. It needs also to improve pricing."
"Pushing global rules and policies to all devices from Central isn't easy. You can do it for all endpoints, which is fine. But you can't do the same with firewalls. Firewall management with Central is very limited. You can connect one firewall to another and tell it, "I want one policy for all my customer's firewalls," but that's not possible. For a customer with multiple firewalls, you can't say, "This works for France, Great Britain, Canada," and push it. It's not possible."
 

Pricing and Cost Advice

"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"This is an expensive solution."
"Cortex XDR’s pricing is very reasonable."
"I don't recall what the cost was, but it wasn't really that expensive."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"It's a yearly fee and depends on what you are looking for."
"The cost is quite affordable."
"Though I don't know the exact price of the product, I know that the tool is worth the money."
"Sophos Central is an affordable solution that any mid-level customer can buy."
"It is not cheap, it is expensive. The price is too much."
"When compared to the market, it's relatively more cost-effective."
"It offers the most competitive pricing compared to other vendors."
"Sophos is more cost-effective than other vendors."
"The price is reasonable."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Financial Services Firm
12%
Government
9%
Real Estate/Law Firm
7%
Computer Software Company
7%
Construction Company
18%
Outsourcing Company
11%
Manufacturing Company
10%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise1
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise8
Large Enterprise10
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Corelight?
I have a fortunate experience with pricing, setup costs, and licensing of Corelight Open NDR, as being a principal ar...
What needs improvement with Corelight?
Corelight Open NDR does not need any improvements or additional features in the next releases. The product is excelle...
What is your primary use case for Corelight?
I have been using Corelight Open NDR solution for approximately three years. I leverage the Suricata engine heavily f...
What is your experience regarding pricing and costs for Sophos Central?
My experience with pricing, setup cost, and licensing for Sophos Central shows that it is expensive. However, when yo...
What needs improvement with Sophos Central?
I have noticed pain points around installation. Whenever I want to install on devices that are Windows, it is usually...
What is your primary use case for Sophos Central?
My main use case for Sophos Central is to help protect our endpoints, especially as we have different team members ac...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Corelight Open NDR
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
CarrefourEdnonGrand Canyon EducationSektorCERTTietoevryVolkswagen Financial Services
Information Not Available
Find out what your peers are saying about Corelight Open NDR vs. Sophos Central and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.