No more typing reviews! Try our Samantha, our new voice AI agent.

Huntress Managed EDR vs Tanium comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Huntress Managed EDR
Ranking in Endpoint Detection and Response (EDR)
6th
Average Rating
9.2
Reviews Sentiment
7.5
Number of Reviews
64
Ranking in other categories
Managed Detection and Response (MDR) (1st)
Tanium
Ranking in Endpoint Detection and Response (EDR)
23rd
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
23
Ranking in other categories
Vulnerability Management (24th), Endpoint Protection Platform (EPP) (14th), Unified Endpoint Management (UEM) (8th), Autonomous Endpoint Management (3rd)
 

Mindshare comparison

As of August 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.7%, down from 3.8% compared to the previous year. The mindshare of Huntress Managed EDR is 2.9%, up from 2.7% compared to the previous year. The mindshare of Tanium is 2.1%, down from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.7%
Huntress Managed EDR2.9%
Tanium2.1%
Other91.3%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Abhishek Saini - PeerSpot reviewer
Professional Services Engineer at Next7 IT
Managed detection has transformed incident response and now delivers faster, focused protection
Overall, my experience with Huntress Managed EDR has been very positive. If I were to suggest improvements, I would like to see more advanced customization and reporting capabilities, particularly for MSPs managing multiple clients. For example, additional dashboard customization, more granular alert filtering options, and enhanced executive level reporting would help teams present security insights more effectively to their clients. Deeper integrations with a broader range of third party security and IT management platforms could also streamline workflows and reduce the need to switch between multiple tools. Another area of improvement would be expanding automation options for common remediation tasks, allowing security teams to respond even more quickly to certain types of threats while maintaining appropriate control. These are more enhancements than shortcomings, as Huntress Managed EDR already provides strong threat detection, excellent SOC support, and an easy-to-manage platform that delivers significant value in day-to-day operations. A few additional enhancements would make the platform even stronger, especially for MSPs managing a large number of endpoints and clients. From a user interface perspective, I would like to see more customizable dashboards that allow engineers to tailor views based on the client's priorities, threat levels, or operational metrics. Another useful feature would be additional automation and authorization options for common response actions such as isolating devices, initiating remediation workflows, or integrating with ticketing systems and SIEM platforms. Overall, these would be valuable additions, but they do not take away from the core strength of Huntress Managed EDR.
Sandeepraj Gatla - PeerSpot reviewer
Dfir Analyst at a tech services company with 201-500 employees
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use. We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5. Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution doesn't need a high level of technical training."
"Monitoring is most valuable."
"The user interface of the solution is sophisticated and straightforward."
"It's a perfect solution. It integrates well into the environment."
"After deploying Traps, we saw the performance of the network improve by 65 to 70 percent."
"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"Huntress Managed EDR has helped significantly reduce our workload so that our engineers can focus on other tasks at hand."
"Huntress helped us to reduce the need for expensive security tools or expensive security analysts. That's very important, especially with us being a a smaller business. Not having to purchase larger software has been great."
"While threat hunting is undoubtedly the most valuable feature, the combination of IP scanning, foothold identification, and canary monitoring has also proven to be incredibly beneficial."
"Because of the pricing, performance, and usability, Huntress Managed EDR is without a doubt the best EDR solution for small businesses that I've ever seen."
"The endpoint protection is definitely the most impactful feature for clients. It just works. It is a set-it-and-forget-it type of solution."
"I would absolutely recommend Huntress Managed EDR, as I consider them a leader in the field and am confident in their service."
"Huntress Managed EDR is probably the easiest solution to use, both to deploy and to maintain, of all the product lines and vendor partnerships we have."
"The most valuable aspect of Huntress is its 24/7 SOC service."
"Tanium is highly scalable."
"Tanium has made the process of detecting threats more proactive with its detection. So, the process is easier and more efficient."
"Tanium's most valuable feature is its instant discovery aspect."
"Tanium is used for endpoint management, specifically patching and configuration management."
"The solution's technical support is very responsive."
"The most valuable features of this solution are the consolidation of all historical data on device endpoints, security drivers, firmware, and Software version gaps."
"The product is granular and can build complex roles compared to other EDR vendors."
"Tanium’s best features include support for any Windows, Linux, or Mac endpoint, regardless of where it is, and the ability to do IT operations and security operations."
 

Cons

"There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
"There's room for improvement with Mac device installations, which can be challenging."
"The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
"There are some limitations on the Traps agents."
"Dashboards do not allow everyone to see what's happening."
"Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"The solution needs better reports. I think they should let the customer go in and customize the reports."
"The product could be improved in terms of customization options available for reports."
"One issue is the managed antivirus. Huntress takes control of the antivirus built into Windows Defender, but it doesn't if, for some reason, Defender isn't working properly and doesn't attempt to fix it. We have to fix it with some scripts so that Defender reports correctly to Huntress. It would be nice if they took that action on our behalf. If they saw a problem with Defender, they should roll out a fix."
"The reporting could be improved by providing a more simplified report that can be easily understood by clients. A way to present the data to the client so they understand its importance would be beneficial."
"To enhance the platform, I suggest adding a feature to forward Huntress's recommended response directly to the client, ensuring their clear understanding of the gathered information."
"Installing Huntress on a Mac presents a challenge for end users due to the operating system's security features, which require administrator privileges for installation."
"Some of Huntress' reporting could be improved."
"There are some drawbacks in Huntress Managed EDR, particularly with the security awareness training aspect which is more manual than expected compared to something like KnowBe4."
"I'd like Huntress to implement a component that can analyze network traffic for specific sites."
"We set a policy to block USB access. The moment a device is being set up on the network, I apply the policy, but it does not come into effect immediately."
"The solution can give a lot of false positives."
"There are some bugs in the product. The tool needs to improve in the area of reporting."
"Any movement into a SaaS solution has challenges since the processes and data flows are not well defined. Hence, you need to build it at the same time."
"The performance could improve in future releases. We have had performance issues in specialized web environments, but overall I think the problems are less than 2% of the computer systems being used."
"The most painful thing is the interface. It's a bit unclear sometimes."
"Most of the time, agent-relative issues have to be more equipped with self-healing features. At times, the agent is there, but for some reason, it doesn't report a status. It gives certain problems that are obviously agent-based."
"We had some issues with the solution's OS upgrade."
 

Pricing and Cost Advice

"The pricing is okay, although direct support can be expensive."
"I am using the Community edition."
"The cost depends on your chosen license type, like Pro or other licenses."
"Its pricing is kind of in line with its competitors and everybody else out there."
"This is an expensive solution."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"Cortex XDR's pricing is ok."
"The tool's price is moderate."
"While other options have emerged since Huntress' arrival, I believe it still offers the best value for the features and services it provides."
"It is fair. They provide good value for the product that they deliver. I have had one price increase in the entire time I have used them. They added a bunch of features and then said that they have to increase our price a little bit. That is a fair way to handle it."
"I believe Huntress offers competitive pricing overall."
"The solution is cheap compared to other alternatives. It offers good value for money. For the whole solution, it's up to about five pounds per device per month. Considering what it does, I think that's very good value."
"I rate the product's price a five or six on a scale of one to ten, where one is cheap, and ten is expensive since it is a fairly priced product."
"The Huntress pricing is an excellent value for what the product provides."
"It is simple. It is reasonable. They raised my prices this year. We never like price increases, but they continue to add value, so we just keep adding agents as we grow and as our clients grow."
"It is very fair. I started at $2.50 and now I am at $3.50. When I signed up, I thought it was too cheap. It now reflects the price. It is very fair. I do not think you can find anything better."
"The solution is expensive but it's a good investment."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"It's an expensive solution. It would be nice if the cost were lower."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"There is an annual license required to use this solution."
"The solution offers value for money."
"It is higher than some competitors in the market."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Computer Software Company
11%
Manufacturing Company
9%
Comms Service Provider
7%
Outsourcing Company
7%
Financial Services Firm
14%
Government
10%
Manufacturing Company
9%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business63
Midsize Enterprise6
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise12
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Huntress?
Overall, my experience with Huntress Managed EDR has been very positive. If I were to suggest improvements, I would l...
What is your primary use case for Huntress?
I have been using Huntress Managed EDR for approximately two years. My primary use case for Huntress Managed EDR has ...
What advice do you have for others considering Huntress?
Huntress Managed EDR's twenty-four-seven SOC support has had a positive impact on our security operations because it ...
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Tanium Inc Cloud, Tanium XEM
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about Huntress Managed EDR vs. Tanium and other solutions. Updated: June 2026.
908,834 professionals have used our research since 2012.