No more typing reviews! Try our Samantha, our new voice AI agent.

Expel vs Palo Alto Networks Cortex XSOAR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Expel
Ranking in SOC as a Service
4th
Average Rating
9.0
Reviews Sentiment
8.2
Number of Reviews
1
Ranking in other categories
Managed Detection and Response (MDR) (14th)
Palo Alto Networks Cortex X...
Ranking in SOC as a Service
2nd
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
61
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd)
 

Mindshare comparison

As of August 2026, in the SOC as a Service category, the mindshare of Expel is 8.2%, up from 6.9% compared to the previous year. The mindshare of Palo Alto Networks Cortex XSOAR is 5.9%, down from 17.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
SOC as a Service Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR5.9%
Expel8.2%
Other85.9%
SOC as a Service
 

Featured Reviews

reviewer2578461 - PeerSpot reviewer
MDR Specialist at a tech services company with 201-500 employees
Rapid threat management and diverse technology integration for effective monitoring
Expel has made it easier for companies to monitor and manage various log sources. With its vast integration portfolio, customers can efficiently monitor diverse environments. Time to value is quick, as Expel can turn their service up very rapidly. They have both automated active responses and human processes that quicken threat resolution.
Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Security automation has transformed incident workflows and now reduces response time dramatically
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX. We have communicated with the vendor team about this, but they are prioritizing product functionality over usability because most target customers are technical and understand a primitive UI. They face difficulties in implementing UI changes as their team is stretched. Thus, the UI/UX of the tool needs significant improvement. There are plans on their roadmap, but a lot remains to be done. Parts of the tool run on an older framework, causing slowness. Usability is a broader issue than features alone. This usability problem is common in many cybersecurity tools, unlike customer-facing applications. Some integrations have speed issues and might not function seamlessly with different upstream configurations, requiring manual updates. These are the main pain points we encountered, particularly with UI/UX, integration speed, and the usability of certain inbuilt playbooks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their threat hunting protocol and process with AI and machine learning are strong, allowing for active and rapid responses."
"The solution provides threat intelligence with EDR."
"The most valuable features are the orchestration because of the way in which it coordinates the loss from all the devices and it provides us with a high-level overview of the critical log information."
"We've had a very positive experience."
"The most valuable feature is automation."
"The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."
"The playbook automation helped streamline my incident response time by removing delays from the human side and reducing the mean time to respond."
"The biggest advantage in Cortex XSOAR that I see is its extensive AI capabilities, where it unifies all your log collection mechanisms and can ingest the logs from almost all of the end devices."
"They have a portal where you can find any kind of integration that you need."
 

Cons

"The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for management."
"It is not a very scalable solution."
"The dashboard performance could be improved."
"It doesn't offer automatic internet reports out of the box."
"Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners."
"The solution's technical support could be better."
"The solution is very expensive."
"Customization and performance can be improved. For example, some formats were incompatible when integrating, and they said we needed to work with the vendor to fix this issue because some logs that AVA logs were not compatible, and it did not readily recognize the format."
"I did notice some drawbacks, as it is a bit complex."
 

Pricing and Cost Advice

Information not available
"It is approx $10,000 or $20,000 per year for two user licenses."
"It's cheaper compared to its competitors."
"The solution's cost is high."
"Palo Alto offers significant discounts to customers who purchase the products repeatedly."
"From the cost perspective, I have heard that its price is a bit high as compared to other similar products."
"The solution's pricing needs improvement."
"There is a perception that it is priced very high compared to other solutions."
"The solution's cost is reasonable."
report
Use our free recommendation engine to learn which SOC as a Service solutions are best for your needs.
908,877 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
11%
Manufacturing Company
9%
Computer Software Company
9%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise9
Large Enterprise32
 

Questions from the Community

What is your experience regarding pricing and costs for Expel?
Expel's pricing has adapted as the market evolved and has become competitive over the past twelve months.
What needs improvement with Expel?
The one area where Expel may not measure up is if a customer requires a managed SIEM as part of their overall solution. There's a gap there, and solutions might require third-party assistance for m...
What is your primary use case for Expel?
I have experience reselling Expel. Customers often come to me wanting to evaluate multiple providers to make a choice based on their specific use cases, requirements, technology investments, and so...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
My experience with pricing, setup cost, and licensing for Palo Alto Networks Cortex XSOAR is that I was just a consumer as an analyst. I was not part of deploying cost, license, procurement, or pro...
What needs improvement with Palo Alto Networks Cortex XSOAR?
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR as a product or at least as a summarizing feature. If that is there, I think it w...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My main use case for Palo Alto Networks Cortex XSOAR is that we use it as a SOAR platform, Security Orchestration and Response tool for our security incidents. I can give you a quick specific examp...
 

Also Known As

Workbench, Expel SOC-as-a-Service
Demisto Enterprise, Cortex XSOAR, Demisto
 

Overview

 

Sample Customers

Amanda Fennell CSO
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Find out what your peers are saying about Arctic Wolf Networks, Palo Alto Networks, LevelBlue and others in SOC as a Service. Updated: July 2026.
908,877 professionals have used our research since 2012.