No more typing reviews! Try our Samantha, our new voice AI agent.

Cybereason Endpoint Detection & Response vs Ivanti Endpoint Security for Endpoint Manager [EOL] comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 4, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.5
Cortex XDR delivers cost savings, reduces security incidents, and attracts customers by replacing multiple solutions, offering high ROI.
Sentiment score
1.0
Cybereason EDR boosts network visibility, reduces threat response time by 50%, and offers ROI in 12-24 months.
Sentiment score
5.8
Ivanti Endpoint Security enhances threat protection, reduces downtime, automates processes, saves costs, and improves operational efficiency.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cyber Security Manager at Welab bank
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
Detection and Response Consultant at Inovasys
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Network Security Engineer at Cyberwell Solution
 

Customer Service

Sentiment score
6.9
Cortex XDR's support is fast and knowledgeable, highly rated despite some regional and process-related challenges.
Sentiment score
5.0
Cybereason's customer service is competent and knowledgeable, though escalations can cause delays, especially without partnership status.
Sentiment score
6.5
Ivanti Endpoint Security support is helpful but needs faster response times and better customization and functionality guidance.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
Head of data centers at a non-profit with 10,001+ employees
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
Senior Process Expert at A.P. Moller - Maersk
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
Chief of IT Architecture at a financial services firm with 10,001+ employees
Nine is great actually since we have people available when we ask, and they know what they are talking about.
Security Delivery Analyst at a consultancy with 10,001+ employees
if you're a partner with them, they provide fairly good support through a concept called invest support.
Head of Research Development and Innovation at CSIR
I rate customer service at eight out of ten as there is room for improvement in response time.
Solutions Architect at M.Tech
 

Scalability Issues

Sentiment score
7.4
Cortex XDR offers strong scalability and flexibility, managing thousands of endpoints efficiently while simplifying cloud-based expansion and integration.
Sentiment score
6.2
<p>Cybereason Endpoint Detection &amp; Response is highly scalable, effectively supporting large organizations with seamless expansion and flexible adaptation.</p>
Sentiment score
7.8
Ivanti Endpoint Security scales well for large organizations, managing up to 160,000 endpoints with strong stability and performance.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Assistant Security Architect at Cloudnomics
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Junior Security Analyst at ITSEC Asia
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
Head of data centers at a non-profit with 10,001+ employees
On a scale from one to ten, the scalability of Ivanti Endpoint Security for Endpoint Manager would be rated between eight and ten.
Solutions Architect at M.Tech
 

Stability Issues

Sentiment score
8.0
Cortex XDR is praised for stability, reliability, minimal bugs, and superior performance, despite occasional false alerts and update issues.
Sentiment score
5.5
Cybereason EDR is reliable with occasional upgrade issues, but improves system speed, and support resolves performance concerns.
Sentiment score
8.2
Ivanti Endpoint Security is stable, with high ratings, but some users report agent-related stability issues challenging to fix.
Cortex remains fast and responsive, even with increasing data and alerts.
Final Year Student at Gitam University
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Senior Process Expert at A.P. Moller - Maersk
Cortex XDR by Palo Alto Networks can be trusted completely.
Soc Analyst at Softcell Technologies Limited
We inform Cybereason about any issues, and they work on a new solution, either with an update or a custom fix in anticipation of the next update.
Security Delivery Analyst at a consultancy with 10,001+ employees
 

Room For Improvement

Cortex XDR needs interface improvements, better integrations, cost-effectiveness, enhanced automation, real-time monitoring, and ease of use.
Cybereason needs better support, simpler deployment, and enhanced features, including automation, dashboard design, and compatibility improvements.
Ivanti Endpoint Security needs improvements in mobile onboarding, troubleshooting, integration, UI, policy management, and non-Windows patching.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
Final Year Student at Gitam University
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Pre Sales Architect at network techlab
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Cyber Security Information Security Specialist at MHM Holding GmbH
Navigation could be better optimized for quick navigation by the user.
Solutions Architect at M.Tech
 

Setup Cost

Cortex XDR offers advanced features with perceived high costs, pricing varies by organization size, subscription, and potential extra feature charges.
Cybereason offers a competitively priced, comprehensive EDR solution with potential cost benefits for experienced users in enterprises.
Ivanti's Endpoint Security pricing is variable and potentially high, justified by its customizable license plans and enterprise value.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
Consultant at a tech services company with 1,001-5,000 employees
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Senior Process Expert at A.P. Moller - Maersk
Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Soc Analyst at Softcell Technologies Limited
 

Valuable Features

Cortex XDR excels in threat detection and response with AI integration, multi-layered security, and user-friendly automation features.
Cybereason EDR offers real-time threat visibility, automatic isolation, and extensive threat-hunting for efficient endpoint management and minimal false positives.
Ivanti Endpoint Security offers comprehensive patch management, inventory control, and a user-friendly interface for efficient cross-platform device management.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
Cyber Security Manager at Welab bank
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
Pre Sales Architect at network techlab
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
Final Year Student at Gitam University
What I find most valuable is the clarity of the platform.
Security Delivery Analyst at a consultancy with 10,001+ employees
Ivanti Endpoint Security for Endpoint Manager is cloud-based, which aids in deployment.
Solutions Architect at M.Tech
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Cybereason Endpoint Detecti...
Average Rating
7.8
Reviews Sentiment
5.6
Number of Reviews
22
Ranking in other categories
Endpoint Protection Platform (EPP) (36th), Endpoint Detection and Response (EDR) (36th)
Ivanti Endpoint Security fo...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2642739 - PeerSpot reviewer
Security Delivery Analyst at a consultancy with 10,001+ employees
User-friendly platform and dashboards provide comprehensive insights
I would like to see improvements on the operational side, specifically in grouping. Currently, I can group sensors into a custom group and assign policies, but I feel it is a shame that I cannot create groups of groups with inheritance. This would be useful for organizing multiple sites or countries into a single group containing multiple sub-groups. Additionally, in the whitelisting case, if I want one policy to have specific whitelisting, but not all the machines in that policy to have it, I could use multiple groups belonging to the same parent group. It is a bit disappointing that whitelisting can only be done via policies and not for individual machines. If I need to whitelist for only one machine, I must create a specific policy. This poses a challenge with two thousand endpoints, making it nearly impossible to create two thousand different policies.
Sanjay Mukhopadhyay - PeerSpot reviewer
Director - Sales & Operations - India at Intertec Systems
A solid low-code builder that helps build workflows and processes in a variety of settings
It's not complex, but you need certified skills for setup to be easy. It is different for an L1 resource, who has a basic understanding of things and may not be a developer who deeply understands how to build up the solution, where that understanding is present with an L3 or L2 resource. For maintenance, you need at least one skill set for each module. You would need one for UEM and one more for MDM, which is the ideal way to do it unless you have people who know the modules in and out. We have a larger team for IT service management because the demand for IT service management is high, but we can see that for other modules as well now.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
14%
Outsourcing Company
12%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
12%
Comms Service Provider
8%
Construction Company
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise5
Large Enterprise12
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise4
Large Enterprise5
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your primary use case for Cybereason Endpoint Detection & Response?
My main use case for Cybereason Endpoint Detection &amp; Response is mostly for incident response.
What needs improvement with Cybereason Endpoint Detection & Response?
When it comes to advanced threats, it sometimes helps me with finding them and hunting them down with threat detectio...
What advice do you have for others considering Cybereason Endpoint Detection & Response?
I mostly work with incident response, so I work with a bunch of them interchangeably, but mostly with the EDR compone...
What needs improvement with Ivanti Endpoint Security for Endpoint Manager?
Some of the GUI features need improvement. In particular, navigation could be better optimized for quick navigation b...
What is your primary use case for Ivanti Endpoint Security for Endpoint Manager?
I use Ivanti Endpoint Security for Endpoint Manager ( /products/ivanti-endpoint-security-for-endpoint-manager-reviews...
What advice do you have for others considering Ivanti Endpoint Security for Endpoint Manager?
I rate the solution eight out of ten overall. Among the AI features, it's used for discovery and remediation. The nav...
 

Comparisons

 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Cybereason EDR, Cybereason Deep Detect & Respond
LANDesk Security Suite, Ivanti Endpoint Security
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Lockheed Martin, Spark Capital, DocuSign, Softbank Capital
Otkritie Bank, France T_l_visions, MBDA, 21st Century Oncology, Sealed Air Corporation, Granite School District, The Bunker, The MAC Services Group, Adams 12 Five Star Schools District, AlliedBarton Security Services, Mohawk Industries, Sun National Bank
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,422 professionals have used our research since 2012.