No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Insight XDR vs Secureworks Taegis XDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon Insight XDR
Ranking in Extended Detection and Response (XDR)
2nd
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
138
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (3rd), Threat Intelligence Platforms (TIP) (2nd), Endpoint Detection and Response (EDR) (2nd), Attack Surface Management (ASM) (2nd), Identity Threat Detection and Response (ITDR) (1st), AI-Powered Cybersecurity Platforms (3rd)
Secureworks Taegis XDR
Ranking in Extended Detection and Response (XDR)
14th
Average Rating
8.8
Reviews Sentiment
6.1
Number of Reviews
10
Ranking in other categories
Network Detection and Response (NDR) (9th)
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of CrowdStrike Falcon Insight XDR is 9.2%, down from 16.5% compared to the previous year. The mindshare of Secureworks Taegis XDR is 1.2%, down from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon9.2%
Cortex XDR by Palo Alto Networks4.5%
Secureworks Taegis XDR1.2%
Other85.1%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Dipak M Gohil - PeerSpot reviewer
IT Manager at Jord International Pty Ltd
Efficient threat detection and seamless deployment improve overall security
The single panel console of CrowdStrike Falcon is very user-friendly, which is what we are looking for. Having multiple administrators between various offices with this single console gives us the ability to see all offices, branch offices, and partners, making it very useful to detect machines, identify machines, and check security risks. Everything in the single console is very useful. CrowdStrike Falcon has positively impacted our organization in terms of efficiency because it's very lightweight, easy to deploy, easy to manage, and works very efficiently. It quickly detects issues and doesn't have a signature-based system, so it works fast and takes immediate action.
Mohammad Jundiah - PeerSpot reviewer
Solutions Architect at Qatar Datamation Systems
Centralized monitoring has strengthened threat hunting and improved ransomware protection
Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network. This monitoring and reporting can be conducted weekly or monthly. Centralized security monitoring and reporting is one of the most valuable aspects, as security fundamentally revolves around compliance. Having a centralized security monitoring platform that detects endpoints, networks, and cloud environments, including servers and switches, is essential. Secureworks Taegis XDR's architecture involves a collector device that collects all your data, even from small laptops, and allows you to monitor everything in one platform. This centralized system provides compliance and security visibility, ensuring evidence and visibility for your security and any compliance requirements you have. Analytics with Secureworks Taegis XDR give you a full preview of everything on your device. It takes all the inputs and outputs of your infrastructure; for example, if it is a firewall, it scans all of the traffic. While it is not a SIEM, it is an open XDR, which excels at conducting analytics. This represents one of its best features because Secureworks has implemented a machine learning model that can detect and analyze everything independently, providing AI-driven features. Integration with third-party tools is quite seamless. Secureworks Taegis XDR can integrate with virtually anything. One of the best features of this product is its integration capabilities with multiple sources of EDRs and any operating system, whether protecting Linux or Windows servers. It boasts very good integration, and if a specific integration is not available, you can raise a ticket to Secureworks, and they will work on your integration, whatever it is, even if it is custom-built software. Secureworks Taegis XDR absolutely aids in efficiency. SOC augmentation extends an organization's existing SOC, which helps reduce alert fatigue significantly. It provides additional threat intelligence and expert investigation, making it very useful for organizations that have a security team but lack twenty-four seven coverage.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"WildFire AI is the best option for this product."
"Overall, it's a great platform; it integrates very well with other solutions from Palo Alto and also with our vendors, the ease of use is excellent, I love the root cause analysis from Cortex, which is amazing, and in a few clicks you can have the full root cause."
"Cortex XDR by Palo Alto Networks is specifically designed to prevent zero-day attacks and is part of an ecosystem of Palo Alto, providing customers with a long-term vision to modify and redesign how security is applied in their company."
"The product's initial setup phase is very easy."
"Its ability to react to cyber data attacks is awesome. That is pretty much the use of it. What blows your mind is the ability to access your assets remotely and see what is actually going on with them. You can not only see them in a console. You can also react very rapidly to your assets that are compromised."
"The protection offered by this product is good, as is the endpoint reporting."
"The solution is a new generation XDR that has a lot of artificial intelligence modules."
"From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference."
"The DLP is the most valuable feature of CrowdStrike Falcon."
"The EDR is amazing and ease of integration with Splunk is a big plus. Integration with BigQuery is also a plus for me and workflow creation is easy. Overall, CrowdStrike Falcon is a great product."
"CrowdStrike has a much lower rate of false positives than Cylance and the dashboard makes it easier to use."
"Easy to use, intelligent, and stable threat detection software."
"The anomaly detection is the most valuable feature."
"I like the Overwatch feature the most."
"CrowdStrike Falcon has been very low maintenance."
"The UI is simple and self-explanatory. Everything is easy to understand."
"The auto-triage feature of Secureworks Taegis XDR makes my workflow easier and efficient, helping me shorten the time of responding to every alert, make my activities productive, and manage everything that I need to check every alert and detection."
"The price for Secureworks Taegis XDR is very competitive."
"It's a complete solution package."
"The initial setup was straightforward."
"Secureworks Taegis XDR has positively impacted our organization by improving detection rates and reducing our time; as I mentioned, it saves us from manually going through all the logs, which is not practical."
"Threat hunting and SOC augmentation represent the most special features about Secureworks Taegis XDR, where some of the best people in cybersecurity proactively search, provide reports, and deliver indicators of compromise for any activity in your network."
"The features I find most valuable are the fact that Secureworks Taegis XDR runs itself without any form of intervention."
"Sophos is a good XDR, and I recommend it for large companies since they have approximately 2,000 or 3,000 devices and can implement it as it is the best XDR."
 

Cons

"We would also like to have advanced tech protection and email scanning."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"The encryption is not up to the mark."
"In general, the price could be more competitive."
"I have faced some issues with Cortex XDR by Palo Alto Networks; there is room for improvement in the sense that certain options prevent us from seeing and segregating data."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"I feel that it should not be a licensed activity because a feature should allow us to see applications running on end devices."
"They are charging for Network Traffic Analyzer (NTA) services, so if the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better."
"The performance could be better. It's a bit slow."
"I would like to see a little bit more in the offline scanning ability."
"CrowdStrike Falcon could improve by having an easier way to search and use the interface for extracting queries from the data. The interface could improve."
"CrowdStrike Falcon could improve the logs by making them free to the API."
"I believe nothing can be done to make CrowdStrike Falcon a ten out of ten, as I think it's one of the best solutions in the market. However, rating it a ten overall would imply there's no scope for improvement, but to survive in the market, changes must be made every day."
"I would like them to improve the correlation of data in the search algorithms. When we run an investigation, malware, phishing, etc., I want to look at multiple endpoints at once to correlate that data to see the likenesses, e.g., how are they not alike or what systems and processes are running across those systems? I don't want to have to run the same search in their Spotlight module five, 10, 15, or 100 times to get 100 different results, copy that data out, and then correlate it on my own. In a very simple way, I want to be able to load up a comma-delimited list giving me the spotlight data on these X amount of hosts, letting me search for it quickly. We have had to go back to CrowdStrike, and say, "Our search are taking far too long for even one host." They did bump up the cores and that did improve performance, but it is still kind of slow to get that Spotlight data. That is probably our biggest pain point. I think that needs some help. I understand this kind of information access is probably not the easiest thing to do. It is probably a big ask depending on how their back-end is setup."
"I would like to see the machine learning feature enhanced."
"For CrowdStrike to work, all the machines need to have an internet connection. This makes it challenging to assist customers without an internet connection. We would like to have a mechanism or relay to make this possible."
"The efficiency or the smooth navigation of the website or the application can be improved in Secureworks Taegis XDR."
"Hardware compatibility could be an area for improvement."
"Customer support for Secureworks Taegis XDR is not that bad; they are reachable but not super efficient."
"To improve Secureworks Taegis XDR, we need to enhance the support part."
"Secureworks Taegis XDR is a good product, but it should include AI technology."
"One negative aspect I always hear from customers is about the cost."
"We found limitations in the XDR's detections, lacking the ability to create customized detection and log parsing rules."
"I do not see any other problems with Secureworks Taegis XDR besides pricing."
 

Pricing and Cost Advice

"It has reasonable pricing for the use cases it provides to the company."
"I am using the Community edition."
"The price of the solution is high for the license and in general."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"It is "expensive" and flexible."
"It's about $55 per license on a yearly basis."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"The solution's pricing is great for us."
"CrowdStrike is well priced. On a yearly basis, it costs between $60 and $100 per user."
"Crowdstrike Falcon is relatively cheap."
"The pricing of CrowdStrike Falcon is competitive."
"The pricing will depend upon your volume of usage."
"When comparing to Microsoft, CrowdStrike Falcon is more expensive."
"With respect to pricing, my suggestion to others is to evaluate the environment and purchase what you need."
"Years ago, when we bought CrowdStrike, you got everything it had. I was a little concerned when they broke this out into a la carte modules where you can buy EDR, Spotlight, etc., picking and choosing off the menu. I was a little worried that the solution would get watered down. However, I realized in my previous organization when we had the full suite that there were a bunch of features in it that we didn't have time to operationalize. So, I warmed up to it. I get the whole, "Look, you can pick and choose. Okay, everybody buys a steak, but do you want mashed potatoes, or do you want lobster mac and cheese?" So, you can pick the sides that you want, so you can buy the solution that you want and operationalize versus paying a lot of money and getting a bunch of things, but not using 60 percent of the tools in the box."
"The pricing is six out of ten."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
909,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Financial Services Firm
10%
Manufacturing Company
10%
Computer Software Company
9%
Government
5%
Financial Services Firm
16%
Manufacturing Company
12%
Computer Software Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business54
Midsize Enterprise34
Large Enterprise63
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
What needs improvement with Secureworks Taegis XDR?
To answer how Intercept X with XDR can be improved as an end customer, I would need to sit down with the solution. In...
What is your primary use case for Secureworks Taegis XDR?
I am working with Trend Micro Vision One, mostly MCC Vision One, for smaller customers. I see a lot of customers opti...
What advice do you have for others considering Secureworks Taegis XDR?
I do have feedback about the customizable workflows. I have a customer who has pretty much loaded the XDR agents on h...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
Secureworks Taegis NDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about CrowdStrike Falcon Insight XDR vs. Secureworks Taegis XDR and other solutions. Updated: June 2026.
909,099 professionals have used our research since 2012.