Try our new research platform with insights from 80,000+ expert users

Cortex XSIAM vs Darktrace comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.4
Cortex XSIAM offers significant ROI and reduced staffing needs, though some businesses await full financial assessments.
Sentiment score
7.3
Darktrace enhances security and threat prevention, offering cost-effective solutions with improved visibility and indirect savings despite quantification challenges.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
 

Customer Service

Sentiment score
6.9
Cortex XSIAM customer support varies, with mixed reviews ranging from inadequate responses to helpful, efficient resolutions across different tiers.
Sentiment score
7.7
Darktrace is praised for excellent, responsive tech support, offering prompt issue resolution and proactive assistance with global presence.
It is ineffective in terms of responding to basic queries and addressing future requirements.
The Palo Alto support team is fully responsive and helpful.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
 

Scalability Issues

Sentiment score
7.3
Cortex XSIAM scales easily for enterprises, rated highly for scalability, despite integration reliance concerns, supporting numerous assets and users.
Sentiment score
7.6
Darktrace is highly scalable, supporting various company sizes and seamless integration, efficiently managing large traffic and endpoints.
Without proper integration, scaling up with more servers is meaningless.
Cortex XSIAM is highly scalable.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
 

Stability Issues

Sentiment score
8.2
Cortex XSIAM is highly stable, cloud-based, and dependable, with minimal downtime, excellent reliability ratings, and rare intervention needs.
Sentiment score
8.5
Darktrace is highly rated for its stability, reliability, and smooth performance, meeting security needs without network issues.
The product was easy to install and set up and worked right.
Overall, Cortex XSIAM is stable.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
 

Room For Improvement

Cortex XSIAM needs improvements in integration, performance, usability, and support services, with enhanced automation and developer-friendliness.
Darktrace needs better integration, automation, and interface improvements, plus enhanced pricing, endpoint protection, and user-friendliness for broader appeal.
Obtaining validation for integrations from Palo Alto takes around eight months, which is quite long.
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports.
Cortex could improve the detection and online resolution of security vulnerabilities.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
Darktrace could improve by integrating with email security gateways like Mimecast or Ironscales.
The intelligence section and the incident view should be seamlessly connected in one view to avoid jumping between pages.
 

Setup Cost

Cortex XSIAM is competitively priced compared to Splunk and Microsoft Sentinel but involves complex licensing and additional costs.
Darktrace is often seen as costly, yet some justify it for its advanced features and customizable licensing.
The first impression is that XSIAM would be more expensive than others we tried.
The product is very expensive.
Cortex XSIAM is pretty expensive, and the licensing process is not very comfortable.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
 

Valuable Features

Cortex XSIAM provides advanced threat detection with machine learning, seamless third-party integration, and comprehensive network and endpoint protection.
Darktrace excels in AI-driven threat detection, autonomous response, and user-friendly interface, making it a top cybersecurity solution.
One of the valued aspects of the product is its use of artificial intelligence to detect security vulnerabilities.
The flexibility for creating manual workflows stands out.
Its signature-less subscriptions and robust detection power stand out in improving threat detection.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
The most valuable features are the AI and advanced learning tools that distinguish it from other products.
 

Categories and Ranking

Cortex XSIAM
Ranking in AI-Powered Cybersecurity Platforms
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
12
Ranking in other categories
Security Information and Event Management (SIEM) (17th), Identity Threat Detection and Response (ITDR) (6th)
Darktrace
Ranking in AI-Powered Cybersecurity Platforms
2nd
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
79
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), AI-Powered Chatbots (2nd), Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Attack Surface Management (ASM) (3rd)
 

Mindshare comparison

As of May 2025, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XSIAM is 10.8%, up from 3.1% compared to the previous year. The mindshare of Darktrace is 23.4%, down from 30.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms
 

Featured Reviews

AKASH MAJUMDER - PeerSpot reviewer
Incident response times have significantly reduced with efficient device integration and log parsing capabilities
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, similar to a feature available in Cortex XDR. The AI analytics need fine-tuning because some use cases are not working from my side.
Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
849,963 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Manufacturing Company
10%
Financial Services Firm
10%
Government
7%
Computer Software Company
14%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cortex XSIAM?
It is an effective solution in terms of performance and functionalities.
What is your experience regarding pricing and costs for Cortex XSIAM?
The licensing cost of Cortex XSIAM is more or less the same as Splunk, making it quite expensive compared to other tools. There are additional expenses for more functionalities.
What needs improvement with Cortex XSIAM?
Cortex XSIAM needs improvements in terms of data onboarding, parsers, and third-party integration supports. Additionally, a future update request is to enable tagging of endpoints in groups, simila...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
 

Overview

 

Sample Customers

Information Not Available
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Find out what your peers are saying about Cortex XSIAM vs. Darktrace and other solutions. Updated: April 2025.
849,963 professionals have used our research since 2012.