No more typing reviews! Try our Samantha, our new voice AI agent.

FortiXDR vs Trellix Endpoint Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
FortiXDR
Ranking in Extended Detection and Response (XDR)
31st
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Trellix Endpoint Security P...
Ranking in Extended Detection and Response (XDR)
8th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
167
Ranking in other categories
Endpoint Protection Platform (EPP) (7th), Endpoint Detection and Response (EDR) (8th)
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of FortiXDR is 1.2%, up from 0.7% compared to the previous year. The mindshare of Trellix Endpoint Security Platform is 3.4%, down from 3.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.5%
Trellix Endpoint Security Platform3.4%
FortiXDR1.2%
Other90.9%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
LL
Integration capabilities enhance compatibility across various cloud environments
I have extensive experience using Fortinet solutions, especially FortiXDR. I have implemented perimeter security in Azure, utilizing features such as web application firewall, application control, and security management.  I specialize in security for data centers, using various Fortinet solutions…
AmitKumar22 - PeerSpot reviewer
Product Manager at Frontier Business systems
Strong endpoint protection has simplified compliance and reduced effort for large user environments
One of the best features of Trellix Endpoint Security Platform is its endpoint security, and I have been using it for the last four and a half to five years, so I can say this is one of the best EDR endpoint security solutions I have ever seen. The features that make Trellix Endpoint Security Platform stand out for me are ease of use and analytics, which I really appreciate the most. Trellix Endpoint Security Platform positively impacts my organization, ensuring we are compliant with SOC 2, HIPAA, and all other compliance requirements, so there are no issues with that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool's use cases are relevant to security."
"I've found the solution to be highly scalable for enterprises."
"But overall, when we speak about security and protection, they are one of the top providers."
"One thing that I like about Cortex XDR by Palo Alto Networks, it is detecting all the suspicious or malicious binaries, and it has integration with Palo Alto Firewall."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"Implementing Cortex XDR by Palo Alto Networks has had a significant impact on my security analyst workload because it becomes much easier."
"They have a new GUI which is just fantastic."
"They did what they said, and this solution could apply to any scenario."
"FortiXDR is valuable for its integration capabilities with one hundred percent compatibility with other vendors in cloud environments like Google, Oracle, and Microsoft."
"The most valuable feature of FortiXDR is its ability to block clients, providing comprehensive endpoint protection."
"The most valuable feature of FortiXDR is it integrates well with other Fortinet solutions, such as Fortinet firewall, FortiMail, FortiSandbox, Forti Fabric, switches, and access points. Whatever the flow of the traffic comes in or goes out, the entire traffic can be managed and monitored properly."
"The product is stable enough."
"Our customers are satisfied with FortiXDR."
"The most valuable feature is the integration between environments."
"It's easy to use."
"McAfee is working perfectly, the productivity itself is great, there are really a lot of features, the endpoint administration is very easy, the initial setup was simple, the stability has been great, and you can scale the product."
"With the rise of malware and, recently, ransomware cases, using VSE assures you a positive Return-on-Investment."
"The features of Trellix Endpoint Security Platform have greatly improved my day-to-day work; I no longer lose sleep over potential data breaches or ransomware attacks as the solution gives me peace of mind, allowing my users to work from various locations with less concern about security."
"I would like to recommend the solution; it's better and, pricing wise, it's worth it, especially compared to other advanced malware security solutions in the market that are very costly."
"The remote installation capabilities are very helpful for us."
"McAfee MVISION Endpoint is used for endpoint protection and protects the files and network against viruses and malware."
 

Cons

"This is a very costly product."
"The tool needs to be improved in terms of integration and interface."
"Previously, the endpoint would leave the environment, not being on our VPN, essentially unable to interact with the server to upload files. It was unable to retrieve new file verdicts. It was using a thing called "local analysis" to determine if something was a malicious file or not. There was no dynamic analysis."
"There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
"Cortex XDR could be improved with more GUI features."
"A better pricing plan would make this product more competitive."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"The pricing of FortiXDR should be improved. It's a point of concern for us."
"Improvement is needed in the intuitiveness and integration measures of FortiXDR, especially in terms of compatibility."
"Many of the solutions, such as CrowdStrike have an MDR solution where remediation can be provided by the vendor. For example, if there is any zero data threat found, a new threat that the customer is not able to recognize, fix, or understand what needs to be done this feature has to be added in FortiXDR so that the customer feels comfortable."
"They could change their licensing costs to make it more affordable for smaller businesses."
"The security of this solution needs improvement."
"Currently, Trellix Endpoint Security can't find the running mutexes, while other open-source products can do it."
"Continued available training is important for people coming in to use it."
"An area in need of improvement involves the overview, which usually does not enable one to get the value in reports."
"We would like to see all the features available on cloud."
"We’re facing remote installation issues sometimes:"
"Search feature could be made more user-friendly."
"There are a few things I wish the folks at Intel would fix."
 

Pricing and Cost Advice

"Our license will require renewal in August, after which the maintenance will continue as usual."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"It has reasonable pricing for the use cases it provides to the company."
"It has a yearly renewal."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"This is an expensive solution compared to other vendors, such as Check Point."
"It provides good value by striking a balance between cost-effectiveness and feature richness."
"The solution is not an expensive tool. Compared to other options, it's mostly average-priced. I've deployed it for customers ranging from 100 nodes to over 5,000 nodes. Its renewal prices are very low, and it offers both perpetual and subscription licenses. With a perpetual license, the product will keep working as long as it's not end-of-life, which benefits companies."
"I do licensing on an annual basis and this is what I always recommend to my clients over the monthly option."
"The product is expensive."
"This product is costly."
"Annual license fee is good"
"It is not that expensive. There is no additional cost. We got the entire bundle together."
"The price of this product is good."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Comms Service Provider
10%
Financial Services Firm
10%
Manufacturing Company
10%
Comms Service Provider
17%
Outsourcing Company
8%
Financial Services Firm
8%
Construction Company
7%
Manufacturing Company
10%
Financial Services Firm
9%
Construction Company
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
No data available
By reviewers
Company SizeCount
Small Business68
Midsize Enterprise39
Large Enterprise67
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for FortiXDR?
Comparing to the enterprise level, the pricing is reasonable. However, for some companies, it might be a little high.
What needs improvement with FortiXDR?
They could change their licensing costs to make it more affordable for smaller businesses.
What is your primary use case for FortiXDR?
We are a system integrator and cloud service provider. Although I am in sales and not technical, I am involved with t...
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deplo...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effec...
What is your experience regarding pricing and costs for McAfee Endpoint Security?
I don't have visibility on pricing because it is negotiated by a different team, as I look after the technical side.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
McAfee Endpoint Security, McAfee Endpoint Protection, Intel Security Total Protection for Endpoint, McAfee Complete Endpoint Protection, Trellix Endpoint Security (ENS)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
inHouseIT, Seagate Technology
Find out what your peers are saying about FortiXDR vs. Trellix Endpoint Security Platform and other solutions. Updated: June 2026.
909,725 professionals have used our research since 2012.