

CrowdStrike Falcon Insight XDR and Cortex XSIAM compete in the endpoint detection and response (EDR) category. CrowdStrike appears to have the upper hand in lightweight deployment, while Cortex stands out for AI-driven automation and integration capabilities.
Features: CrowdStrike Falcon Insight XDR provides a lightweight agent, behavior-based detection, and effective threat hunting features. It excels with real-time alerts and seamless remote access for manual analysis. Cortex XSIAM offers AI-driven automation, robust SOAR capabilities, and unified threat assessment across endpoints and networks.
Room for Improvement: CrowdStrike Falcon Insight XDR could enhance dashboard functionality and report customization, as well as reduce false positives and offer on-demand scanning. Cortex XSIAM needs better GUI usability, improved integration capabilities, and enhanced performance optimization for complex environments.
Ease of Deployment and Customer Service: CrowdStrike Falcon Insight XDR works across multiple environments, offering proactive customer support, though response time reviews are mixed. Cortex XSIAM, also supporting various deployment environments, has a complex licensing process, and the support service is helpful but could improve in timely assistance.
Pricing and ROI: CrowdStrike Falcon Insight XDR is priced higher but offers significant operational efficiency benefits. Cortex XSIAM provides competitive pricing with quality offerings, though users may incur additional costs for premium add-ons. Both solutions exhibit strong ROI potential by enhancing security posture.
Catching issues early enough saves us from having to disable multiple users, which may be part of a later phishing event or disruption event in our environment.
We have to have cyber liability insurance, and knowing that we have CrowdStrike Falcon definitely helps when it comes to the bottom line and helping our insurance rates stay at a fair level.
CrowdStrike Falcon saves time and offers good value for money, especially for enterprise companies, because it can stop breaches.
With premium support, core Palo Alto technical experts handle issues directly.
It is ineffective in terms of responding to basic queries and addressing future requirements.
I had a dedicated person allocated for supporting, and even with them, it was very good.
On a scale of one to ten, I would rate the technical support as a 10 because they resolve many issues for us.
Everybody is friendly, knowledgeable, and wants to help, and you can feel that they want to keep your business.
The onboarding team deserved a ten.
Without proper integration, scaling up with more servers is meaningless.
The SOC team is responsible for fully managing Cortex XSIAM.
Cortex XSIAM is highly scalable.
It has adequate coverage and is easy to deploy.
In terms of scalability, I find CrowdStrike to be stable, and I have not encountered any limitations with it.
There's no scalability limitation from CrowdStrike itself, as it just requires agent deployment.
The product was easy to install and set up and worked right.
With continuous integration that the colleagues probably are doing, it is becoming better and better.
Overall, Cortex XSIAM is stable.
I have not experienced any downtime, crashes, or performance issues with CrowdStrike Falcon.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
Cortex XSIAM is on the expensive side and requires substantial improvement in pricing.
Documentation is abysmal and needs to be improved dramatically.
If I bring up a device, I want a quick button there to contain it because if I'm clicking on that device, there's something I'm looking into and most likely I've been alerted of something, so I should probably contain it first and then ask questions later.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
It is approximately 60 dollars per endpoint at MSRP.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
The licensing cost and setup costs are affordable.
The advanced visualization capabilities of the product are important for understanding security trends in an organization.
To have Cortex XSIAM available is to basically have integration of all log sources, all alerting, and so on and so forth from firewalls and different tools, to get everything in one place, and afterwards to be able to build on the information that is coming.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately.
Being an EDR solution, it helps us identify attacks in real-time.
| Product | Mindshare (%) |
|---|---|
| Cortex XSIAM | 1.4% |
| Splunk Enterprise Security | 7.8% |
| IBM Security QRadar | 5.6% |
| Other | 85.2% |
| Product | Mindshare (%) |
|---|---|
| CrowdStrike Falcon | 5.7% |
| Microsoft Defender for Endpoint | 6.5% |
| SentinelOne Singularity Endpoint | 4.5% |
| Other | 83.3% |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
| Company Size | Count |
|---|---|
| Small Business | 58 |
| Midsize Enterprise | 46 |
| Large Enterprise | 83 |
Cortex XSIAM acts as a critical element for SOC foundations, integrating SIEM and EDR capabilities, valued for threat detection and seamless security orchestration with Palo Alto Networks products.
Organizations find Cortex XSIAM beneficial for SOC foundations due to its capability to integrate SIEM and EDR tools, facilitating data collection, detection, and response. It connects with third-party data sources while reducing management effort and offering cost-effective alternatives to competitors like CrowdStrike and Trend Micro. Featuring automation and integration with Palo Alto Networks products, Cortex XSIAM enhances threat detection. Unified architecture allows a comprehensive view of attacks, further supported by machine learning and integration with existing vendor solutions, ensuring that users gain insights without significant manual log analysis.
What are Cortex XSIAM's key features?
What benefits are evident in Cortex XSIAM reviews?
Industries implement Cortex XSIAM mainly in technology-driven sectors where centralized endpoint protection and automation of forensic investigation are paramount. By integrating several third-party systems for incident response, companies in competitive markets leverage its attributes for heightened operational security efficiency. However, users note areas for improvement, such as Attack Surface Management and integration enhancements, to better suit tech-heavy industries needing extensive connectivity with cybersecurity solutions.
CrowdStrike Falcon delivers AI-powered endpoint protection, detection, and response to help organizations stop malware, ransomware, fileless attacks, and sophisticated adversaries. Built on the cloud-native Falcon platform and a single lightweight sensor, it combines prevention, EDR, threat intelligence, and automated response to protect endpoints while simplifying security operations.
What features make CrowdStrike Falcon stand out?
What benefits can users expect?
Across industries, CrowdStrike Falcon helps organizations modernize endpoint security, improve security team efficiency, and stop sophisticated threats with AI-powered protection and adversary intelligence.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.