No more typing reviews! Try our Samantha, our new voice AI agent.

Coro vs Huntress Managed EDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
6th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
112
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Coro
Ranking in Endpoint Detection and Response (EDR)
62nd
Average Rating
0.0
Reviews Sentiment
3.1
Number of Reviews
1
Ranking in other categories
Email Security (46th), Data Loss Prevention (DLP) (71st), Endpoint Protection Platform (EPP) (52nd)
Huntress Managed EDR
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
9.2
Reviews Sentiment
7.5
Number of Reviews
60
Ranking in other categories
Managed Detection and Response (MDR) (1st)
 

Mindshare comparison

As of June 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.5%, down from 4.0% compared to the previous year. The mindshare of Coro is 0.7%, up from 0.6% compared to the previous year. The mindshare of Huntress Managed EDR is 3.2%, up from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Huntress Managed EDR3.2%
Cortex XDR by Palo Alto Networks3.5%
Coro0.7%
Other92.6%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Vignesh  K - PeerSpot reviewer
Practice Engineer at Cloudunicorn.in
Auto scanning and enhanced security but re-adding protections need improvement
At that time, we observed certain issues with the product. The functionalities could be improved, such as the isolation feature. If we remove our protection, we cannot easily add it back. If, in our organization, we need to remove a specific system for a particular time, we cannot add it back for security after doing so. This is one thing we have experienced. Scalability is also lacking. If we want to do the same thing repeatedly, there's not much the solution offers; it isn't very strong.
JefferyGiddens - PeerSpot reviewer
Director, Information Technology & Cybersecurity at a financial services firm with 51-200 employees
Improving alert visibility and reporting has reduced workload and strengthened security posture
Huntress Managed EDR could be improved by providing more visibility into each alert that comes in and what action was taken on it. There have been times when an alert was received through Microsoft Defender indicating an account was accessed, when in reality it was blocked by a conditional access policy, yet when checking the Huntress portal, that event does not appear at all, lacking indication that it was raised and investigated as not a threat. The reporting in Huntress Managed EDR is fairly basic, as the only available report is effectively an executive summary. Although it contains useful information, other platforms have reporting engines that are much more robust and customizable, functionality that appears to be missing in Huntress.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This software helps us understand any issues that may arise when someone is not at work."
"There has been a significant reduction of approximately 70% to 80% in our internal MTTR and MTTD metrics, now around five to eight minutes whereas previously it was hours, which has helped tremendously."
"The product's initial setup phase is very easy."
"The solution doesn't need a high level of technical training."
"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
"The auto-scanning feature is quite beneficial."
"After deploying Huntress Managed EDR, it took no time to start improving my organization's security."
"Huntress Managed EDR has positively impacted my organization by preventing malware and viruses from attacking our clients."
"Huntress Managed EDR has positively impacted my organization because I can confidently tell clients that I am offering a best-in-class, state-of-the-art MDR solution incorporated within my offerings."
"It is incredibly efficient for our engineering team because Huntress provides all the information needed to fix issues, not just flag them."
"Huntress Managed EDR is probably the easiest solution to use, both to deploy and to maintain, of all the product lines and vendor partnerships we have."
"Huntress' best feature is the threat-hunting expertise that is part of their 24/7 SOC."
"Using Huntress Managed EDR has helped reduce the need for expensive security tools or hiring additional security analysts since I can use that as the first port of call versus trying to get an external SOC."
"It is a ten out of ten in terms of ease of use."
 

Cons

"I recommend adding a data loss prevention (DLP) solution to Cortex XDR by Palo Alto Networks. The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products."
"The dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard."
"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"Cortex XDR could be improved with more GUI features."
"The MAC agent is not as robust feature-wise as the PC version."
"It should support more mobile operating systems. That is one of the cons of their infrastructure right now."
"The functionalities could be improved, such as the isolation feature."
"Scalability is lacking. If we want to do the same thing repeatedly, there's not much the solution offers; it isn't very strong."
"Huntress has a cyber education platform, but it lacks all the languages we need. Since we support customers in different countries, expanding the language options for their training would be beneficial."
"Using Huntress Managed EDR has not reduced our need for expensive security tools or hiring expensive security analysts, as we run redundancy and maintain all that in-house while Huntress serves as a partner, not a replacement."
"One area where Huntress Managed EDR can improve is in alerting."
"I would request that they make it an agent for Linux because we need it on Linux."
"We need an API to automatically retrieve metrics and data about backend activity so we can generate client reports."
"It would be ideal if they could create some incentives to help more partners get clients to onboard it."
"The ITDR product is coming along great, however, we are still getting many false positives."
"Improvements for Huntress Managed EDR really come down to the user interface online, which is less polished than I would like."
 

Pricing and Cost Advice

"The pricing is a little high. It is per user per year."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"The cost depends on your chosen license type, like Pro or other licenses."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"I am using the Community edition."
"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"The price is on the higher side, but it's okay."
Information not available
"I rate the product's price a five or six on a scale of one to ten, where one is cheap, and ten is expensive since it is a fairly priced product."
"The Huntress pricing is an excellent value for what the product provides."
"I believe Huntress Managed EDR is fairly priced. The value I get from it in terms of peace of mind justifies the expense. You can justify it as a business expense."
"We haven't had any problems with Huntress' pricing. We're at 250 workstations, and we've grown considerably this year. They've been able to handle everything that we've thrown at them within that time frame. They're also reducing the price based on how many endpoints we add."
"While other options have emerged since Huntress' arrival, I believe it still offers the best value for the features and services it provides."
"It works well for an MSP."
"Regarding the pricing for Huntress Managed EDR, I was amazed when I heard the price; I thought it was going to be way more than what it is based on the quality."
"It is very fair. I started at $2.50 and now I am at $3.50. When I signed up, I thought it was too cheap. It now reflects the price. It is very fair. I do not think you can find anything better."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
11%
Manufacturing Company
10%
Comms Service Provider
9%
Construction Company
11%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
7%
Computer Software Company
12%
Manufacturing Company
9%
Outsourcing Company
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise20
Large Enterprise52
No data available
By reviewers
Company SizeCount
Small Business61
Midsize Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Coro?
The cost is reasonable because it is aimed at SMB customers, not enterprise customers. The prices are reasonable. We ...
What needs improvement with Coro?
At that time, we observed certain issues with the product. The functionalities could be improved, such as the isolati...
What is your primary use case for Coro?
We have not sold the product to any customers as of now. We are still in the testing phase, which means we, along wit...
What needs improvement with Huntress?
I believe that the new support feature they've added, the managed endpoint protection and response, should be include...
What is your primary use case for Huntress?
My main use case for Huntress Managed EDR is that it lets me sleep at night, knowing that the Huntress team is making...
What advice do you have for others considering Huntress?
The twenty-four hour per day human-led SOC support from Huntress Managed EDR is probably the biggest reason why we're...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Lenovo, Dropbox, T-Systems
Information Not Available
Find out what your peers are saying about CrowdStrike, SentinelOne, Microsoft and others in Endpoint Detection and Response (EDR). Updated: June 2026.
902,270 professionals have used our research since 2012.