No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Insight XDR vs NetWitness NDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
119
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon Insight XDR
Ranking in Extended Detection and Response (XDR)
34th
Average Rating
9.6
Reviews Sentiment
7.0
Number of Reviews
3
Ranking in other categories
No ranking in other categories
NetWitness NDR
Ranking in Extended Detection and Response (XDR)
40th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (47th), Threat Intelligence Platforms (TIP) (34th), Endpoint Detection and Response (EDR) (57th), Security Orchestration Automation and Response (SOAR) (22nd), Network Detection and Response (NDR) (19th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2894520 - PeerSpot reviewer
Senior Manager at a consultancy with 11-50 employees
XDR telemetry has transformed threat hunting and now simplifies correlation across tools
The improvements I have observed in my process for detecting and investigating sophisticated attacks since adopting CrowdStrike Falcon Insight XDR is the quality of the telemetry that it collects. It collects all the right information you need to be able to detect threats and conduct threat hunting. The value I get from correlating activity across endpoints and other security domains with CrowdStrike Falcon Insight XDR ensures that I am actually getting value out of my full security tooling stack, bringing everything together into one spot. Every product has its own blind spots, but when you bring them all together, you get a better picture of what is going on. The detection capabilities of CrowdStrike Falcon Insight XDR have influenced my approach to identifying and addressing sophisticated threats by focusing on the correlation aspects and utilizing multiple data sources to detect those threats rather than having individual detections that utilize only one source. CrowdStrike Falcon Insight XDR has definitely reduced my mean time to detect and mean time to respond, though I could not give exact figures. The impact that CrowdStrike Falcon Insight XDR has had on alert volume and analyst investigation time is definitely reducing the volume of alerts by correlating data sources. Anytime you do that, you are speeding up or reducing the amount of work an analyst does and speeding up the time for them to do things. My experience with CrowdStrike Falcon Insight XDR's behavioral detections and Indicators of Attack has been good overall. I think it is hitting many of the points I have already mentioned in terms of correlating those data sources, making it easier to detect things and easier to investigate them. These detection methods integrate into my current security operations workflows by generally forming the centerpiece. I am actually a consultant, so I do not have a specific workflow myself, but I work with multiple clients, many of them using CrowdStrike Falcon Insight XDR, and it brings in a lot of information and stitches it all together.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
"I like the centralized console and the predictive analysis it does of malware. It is very stable and also scalable."
"Palo Alto is one of the tech vendors that always provides top-of-the-line products."
"The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
"Overall, it's a great platform; it integrates very well with other solutions from Palo Alto and also with our vendors, the ease of use is excellent, I love the root cause analysis from Cortex, which is amazing, and in a few clicks you can have the full root cause."
"The initial setup is pretty easy."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"CrowdStrike Falcon Insight XDR gives us the overhead in terms of resources to make the most of what we have, and anytime I can free up myself to help my end users is a win."
"Without a doubt, CrowdStrike Falcon Insight XDR is making their lives easier."
"CrowdStrike Falcon Insight XDR has positively impacted my organization by allowing us to understand behaviors and how our customers are suffering attacks, enabling us to anticipate those breaches."
"NetWitness Endpoint has enabled us to detect attacks that bypass the first stage of cybersecurity, like zero-day and advanced attacks."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"One of the most valuable features is the Orchestrator."
"I would recommend others to use RSA NetWitness Endpoint at this time because they have evolved from an MD to an EDR solution to an XDR solution."
"It is very easy to use, and its usability is great. The use cases are also very easy. The visualizations of the use cases are magnificent. You cannot find this in any other solution. From my point of view, it is great."
"The interface of this solution is very flexible and easy to use."
"In my opinion, this is the best platform, world-wide, and I am happy with it."
"RSA NetWitness Endpoint has helped our organization from its many advantages and because it provides overall visibility of all of our endpoints within the enterprise network."
 

Cons

"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"There's room for improvement with Mac device installations, which can be challenging."
"I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."
"Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
"The GUI could be improved. It's a little bit cumbersome. It could be more user-friendly."
"It is not a suitable solution if you are looking for a single product with multiple features such as DLP, encryption, rollback, etc."
"It'll help if customization was easier."
"Managing the product should be easier."
"CrowdStrike Falcon Insight XDR can be improved by expanding the number of built-in integrations."
"My experience with pricing, setup cost, and licensing could be better."
"I don't see this solution being very scalable."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge."
"The solution is modular, for example you can buy the RSA ePack, which you buy as a module is not part of the conduit solution. They could include it and have it as an all-in-one solution."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"We would like to see the hunting and investigation features of this solution improved, in order to provide better visibility of issues."
"The problem with this product is that it's a bit slow."
"The contamination feature could be improved."
 

Pricing and Cost Advice

"The price of the solution is high for the license and in general."
"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"I feel it is fairly priced."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"The pricing is a little high. It is per user per year."
"Its pricing is kind of in line with its competitors and everybody else out there."
Information not available
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"It is an expensive product."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
"I do not have any opinion on the pricing or licensing of the product."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
915,383 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
No data available
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise21
Large Enterprise56
No data available
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for CrowdStrike Falcon Insight XDR?
My experience with pricing, setup cost, and licensing for CrowdStrike Falcon Insight XDR is that it is very manageabl...
What needs improvement with CrowdStrike Falcon Insight XDR?
CrowdStrike Falcon Insight XDR can be improved with a little more positive press about how good you are.
Ask a question
Earn 20 points
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about CrowdStrike Falcon Insight XDR vs. NetWitness NDR and other solutions. Updated: September 2026.
915,383 professionals have used our research since 2012.