Coming October 25: PeerSpot Awards will be announced! Learn more

DFLabs IncMan SOAR vs Palo Alto Networks Cortex XSOAR comparison

Cancel
You must select at least 2 products to compare!
Comparison Buyer's Guide
Executive Summary

We performed a comparison between DFLabs IncMan SOAR and Palo Alto Networks Cortex XSOAR based on real PeerSpot user reviews.

Find out in this report how the two Security Orchestration Automation and Response (SOAR) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.

To learn more, read our detailed DFLabs IncMan SOAR vs. Palo Alto Networks Cortex XSOAR report (Updated: September 2022).
634,325 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The vendors themselves will actually help with any customizations a client may require"

More DFLabs IncMan SOAR Pros →

"The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work.""It was useful as a ticketing tool.""Palo Alto has gotten the investigators more presence to actually go in the report because being that the platform will email the investigator that it's been assigned to, now the investigators will jump in there and start going through the review process a lot quicker.""I chose Cortex XSOAR because the client also has Palo Alto firewalls. I can incorporate the data from the Palo Alto firewalls into Cortex and send it into the same data lake to manipulate that data. It lets me manage and monitor the data in one place.""The most valuable feature is automation.""The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information.""The pricing is very good.""They have a portal where you can find any kind of integration that you need."

More Palo Alto Networks Cortex XSOAR Pros →

Cons
"The support is not 24/7."

More DFLabs IncMan SOAR Cons →

"The configuration of the solution could improve it is difficult.""Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated.""Corex XSOAR could be improved by reducing the time it takes to process large amounts of data and increasing the number of integrations.""For building automation, there is not a lot of good documentation. The documentation is there, but it is not very good from my perspective. There should be an improvement in this area. I don't see issues with anything else. In terms of new features, I have heard that other products have EBA functionality. It would be good if this functionality could be added.""There should be an on-premise version available for customers to have different choices.""It is been decommissioned by Palo Alto.""The solution is very expensive.""The integration could be better. Cortex, for example, does not work with iPhone."

More Palo Alto Networks Cortex XSOAR Cons →

Pricing and Cost Advice
Information Not Available
  • "From the cost perspective, I have heard that its price is a bit high as compared to other similar products."
  • "There is a yearly license required for this solution and it is expensive."
  • "It is approx $10,000 or $20,000 per year for two user licenses."
  • "When I first looked at Demisto, it had a price tag of $250,000 but when we finally purchased it, it was $345,000."
  • "The price of Palo Alto Networks Cortex XSOAR is expensive."
  • "The price of Palo Alto Networks Cortex XSOAR could be reduced. We are always looking for a discount. There is an annual license needed to use this solution."
  • "Cortex XSOAR's price could be lower."
  • "The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
  • More Palo Alto Networks Cortex XSOAR Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
    634,325 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The vendors themselves will actually help with any customizations a client may require
    Top Answer:We are the distributor for DFLabs.
    Top Answer:If your organization has its own specific workflow and a set of procedures to follow when a specific incident occurs, then I would recommend this solution. It can be very specific when issuing… more »
    Top Answer:I think Swimlane is a better cost. It's small and doesn't focus on only integrating with it's own products like other XSoar competitors. 
    Top Answer:I chose Cortex XSOAR because the client also has Palo Alto firewalls. I can incorporate the data from the Palo Alto firewalls into Cortex and send it into the same data lake to manipulate that data… more »
    Ranking
    Views
    769
    Comparisons
    560
    Reviews
    0
    Average Words per Review
    0
    Rating
    N/A
    Views
    11,957
    Comparisons
    7,650
    Reviews
    13
    Average Words per Review
    530
    Rating
    8.5
    Comparisons
    Also Known As
    DFLabs IncMan Incident Response
    Demisto Enterprise, Cortex XSOAR, Demisto
    Learn More
    Overview

    DFLabs' Security Orchestration, Automation and Response (SOAR) platform, IncMan SOAR, is designed for SOCs, CSIRTs and MSSPs to automate, orchestrate and measure security operations and incident response processes and tasks, all from within one single, intuitive platform. By integrating security tools, fusing intelligence, sharing knowledge and implementing seamless workflows, IncMan SOAR enables every security incident to be detected, responded to, and remediated in the fastest possible time frame.

    DFLabs IncMan SOAR is the only Security Orchestration, Automation and Response (SOAR) platform capable of full incident lifecycle automation, that includes built-in, automated threat intelligence gathering, risk assessment, triage and notification, context enrichment, hunting and investigating, threat containment and more. This feature rich, unique and scalable SOAR platform provides context to security incidents, automates actions, orchestrates response to activities, while enabling full reporting and measurement functionality across all stakeholders.

    DFLabs covers the entire spectrum of security orchestration, automation and response components as outlined by Gartner, with a unique combination of features and capabilities, driven through continuous improvement and innovation. IncMan SOAR is the only platform to offer full incident response lifecycle management with machine learning and threat hunting. Acting as a force multiplier, it enables security teams to do more with less, empowering security analysts, while ensuring organizations stay one step ahead of any potential threat.

    Automate. Orchestrate. Measure.

    IncMan SOAR provides three critical functions as an enabler to your security program. Automation and orchestration which in turn enables response, as well as measurement.

    Automate

    Augment analysts by automating common, repetitive and menial tasks driven by machine learning for faster response to all alerts.

    Orchestrate

    Establish repeatable, enforceable, measurable and effective incident response workflows, orchestrating your security tool set into one seamless response process.

    Measure

    Measure, benchmark and optimize security operations and incident response activities and performance from one intuitive and collaborative platform.

    Seamlessly Integrate and Orchestrate Your Tools Together as One.

    Improve efficiencies by enabling your security analysts to access and manage all tools, technologies and processes from one intuitive platform. IncMan SOAR supports hundreds of 3rd party security technologies via QIC, API, CEF, Syslog and Email, with a constantly growing list of certified bidirectional integrations and Open Integration Framework for custom integrations.

    Dramatically reduce the mean time to detection, response and remediation of all potential security incidents, ensuring no alert goes untouched.

    See IncMan SOAR in Action.

    Palo Alto Networks delivers a complete solution that helps Tier-1 through Tier-3 analysts and SOC managers to optimize the entire incident life cycle while auto documenting and journaling all the evidence. More than 100+ integrations enable security orchestration workflows for incident management and other critical security operation tasks.

    Palo Alto Networks Cortex XSOAR is a piece of Security Orchestration, Automation, and Response software that redefines what it means for a program to orchestrate security in an automated manner. It is a next-generation solution that offers all of the features of dozens of siloed security operations center tools in one place. Cortex XSOAR combines case management, automation, real-time collaboration, and threat intelligence management to create a platform that can handle all aspects of system security. Teams that make use of Cortex XSOAR can expect to cut the number of issues that they will have to deal with by 75%. At the same time, the speed at which they resolve those issues that slip through will rise by 90%.

    Cortex XSOAR ensures that all of the IT and security tools that you employ function as a unified system. It does this by employing hundreds of integrations that allow you to run a wide variety of programs at once without ever worrying about them interfering with each other. These integrations are limited only by your imagination. They can be used immediately as they are, if that is what you need. However, they can also be customized according to the requirements of your system. This approach provides you with the maximum levels of both flexibility and utility.

    The model that this platform uses is based on a machine learning algorithm. The level of automation allows you to provide more than an unchanging and inflexible blanket of coverage. Cortex XSOAR takes all of the data that it gathers and uses it to expand its protective capabilities. This creates recommendations that you can use to create a threat playbook that can be deployed uniformly throughout your organization.


    Benefits of Palo Alto Networks Cortex XSOAR

    Some of Palo Alto Networks Cortex XSOAR’s benefits include:

    • The ability to have all of your data collected in a single location. Valuable time can be saved now that everything that security analysts need to know in order to diagnose and react to threats has been centralized.
    • Security operations center tasks can be automated. This allows you to assign management and analyst staff to the most essential tasks. The effectiveness of your organization will be increased, which will result in a rise in your company’s overall security and productivity.
    • Many kinds of data can be stitched together by this platform. Network, endpoint, cloud, and identity data can be combined to offer a more complete picture of the threats that are discovered.
    • Integrated threat intelligence management can notify you about threats in real time. Now you can diagnose and address issues as they arise. You can also assign values to the threats so that your resources are being used in the most effective manner possible.


    Reviews from Real Users

    Palo Alto Networks Cortex XSOAR’s centralized monitoring interface and automation are two features that help it stand out. This might help explain why one quarter of the Fortune 500 companies choose Palo Alto Networks Cortex XSOAR over the competition.

    Peerspot users note the effectiveness of these features. One user wrote, “We were looking for a single pane of glass type of solution that would allow us to physically be in one appliance - be able to work in concert with other servers that we have within our environment. We wanted orchestration and automation. The single pane of glass was the most important part.” Another noted, "The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."

    Offer
    Learn more about DFLabs IncMan SOAR
    Learn more about Palo Alto Networks Cortex XSOAR
    Sample Customers
    University of Advancing Technology, Cybersecurity Ventures
    Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
    Top Industries
    VISITORS READING REVIEWS
    Computer Software Company20%
    Comms Service Provider16%
    Financial Services Firm12%
    Government10%
    REVIEWERS
    Government20%
    Financial Services Firm20%
    Healthcare Company10%
    Comms Service Provider10%
    VISITORS READING REVIEWS
    Computer Software Company20%
    Comms Service Provider13%
    Financial Services Firm10%
    Government7%
    Company Size
    VISITORS READING REVIEWS
    Small Business15%
    Midsize Enterprise15%
    Large Enterprise69%
    REVIEWERS
    Small Business30%
    Midsize Enterprise30%
    Large Enterprise40%
    VISITORS READING REVIEWS
    Small Business18%
    Midsize Enterprise15%
    Large Enterprise67%
    Buyer's Guide
    Security Orchestration Automation and Response (SOAR)
    September 2022
    Find out what your peers are saying about Palo Alto Networks, Splunk, Exabeam and others in Security Orchestration Automation and Response (SOAR). Updated: September 2022.
    634,325 professionals have used our research since 2012.

    DFLabs IncMan SOAR is ranked 16th in Security Orchestration Automation and Response (SOAR) with 1 review while Palo Alto Networks Cortex XSOAR is ranked 1st in Security Orchestration Automation and Response (SOAR) with 17 reviews. DFLabs IncMan SOAR is rated 0.0, while Palo Alto Networks Cortex XSOAR is rated 8.2. The top reviewer of DFLabs IncMan SOAR writes "Protects an organization from the threat of a data breach or cyberattack". On the other hand, the top reviewer of Palo Alto Networks Cortex XSOAR writes "Enables the investigators to go through the review process a lot quicker". DFLabs IncMan SOAR is most compared with Splunk Phantom, IBM Resilient, SECDO Platform, Fortinet FortiSOAR and Siemplify, whereas Palo Alto Networks Cortex XSOAR is most compared with Splunk Phantom, Fortinet FortiSOAR, IBM Resilient, ServiceNow Security Operations and Siemplify.

    See our list of best Security Orchestration Automation and Response (SOAR) vendors.

    We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.