No more typing reviews! Try our Samantha, our new voice AI agent.

Intercept X Endpoint vs Kaspersky Anti Targeted Attack comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Extended Detection and Response (XDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Intercept X Endpoint
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (15th), Endpoint Detection and Response (EDR) (19th), ZTNA (12th), Managed Detection and Response (MDR) (11th), Extended Detection and Response (XDR) (15th), Ransomware Protection (5th)
Kaspersky Anti Targeted Attack
Average Rating
6.6
Reviews Sentiment
6.1
Number of Reviews
6
Ranking in other categories
Network Traffic Analysis (NTA) (25th), Network Detection and Response (NDR) (28th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Intercept X Endpoint1.7%
Microsoft Defender for Endpoint7.0%
CrowdStrike Falcon6.2%
Other85.1%
Endpoint Protection Platform (EPP)
Network Traffic Analysis (NTA) Mindshare Distribution
ProductMindshare (%)
Kaspersky Anti Targeted Attack0.9%
Darktrace16.2%
Cisco Secure Network Analytics9.7%
Other73.2%
Network Traffic Analysis (NTA)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
AM
IT Head at Dee Development
Has struggled to detect major threats but has offered basic protection over time
Intercept X Endpoint could learn from CrowdStrike in terms of overall performance and filtering because performance is most important, especially these days as Windows is getting buggier and buggier, which puts a huge load on the PC, and even with the most advanced CPUs and everything in place, it still lags in performance in so many places, thanks to Windows' clumsy design of these collaboration suites that make it extremely heavy on PC's resources. The interface of Intercept X Endpoint is quite old-fashioned. The Sophos interfaces, including for Intercept X Endpoint, are quite bad actually; to be very honest, even in UTM boxes, they are not great at all. You can hardly see a very small portion of windows while it's creating the firewall rules, and we have been complaining about this for quite some time, but there hasn't been any improvement on those grounds. Intercept X Endpoint's anti-ransomware capabilities failed us during a bad attack, and just because of our own backup policies, we could restore our normal operations; otherwise, if we had to depend on this solution, we would have been long dead because the infection was so bad, it couldn't even detect the infection. Intercept X Endpoint cannot handle zero-day attacks; in my experience, last year, we had this major issue with a malware attack, and it happened just because of our backup policies that we were able to recover without any support from Sophos, which just told us they would charge us some 1 Crore in rupees. Intercept X Endpoint should improve their implementation; things will never be perfect for the new world. This new world is always facing new kinds of attacks and new ways to compromise the system. They need to learn fast, implement fast, and sometimes redesigning the solution is the solution—not just patchwork. There was a time we used to love Sophos because of its fresh design and innovative thought. In my experience, when technical companies are led by MBA professionals, they lose their shine on the technical part and become more dependent on target sales; it turns into a marketing-centric operation that loses the technical focus completely.
FarkhundAbbas - PeerSpot reviewer
Security Engineer at adcb
The tool provides excellent sandboxing and email security features, but the backup and recovery features are not good
If my primary solution is down, no backup solution is available to restore it. It is one of the biggest weaknesses of the platform. If I need to update the solution, there is no option to pick the events and the logs from it and deploy it in another solution. The backup and recovery features of the product are not good. I need backup. If the tool is down for some time, I cannot get the logs at that particular time.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"It blocks malicious files, prevents attacks, and doesn't require many updates because it is a very light application."
"Stability is a primary factor, and then there's the ease of distribution and policy management."
"One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
"On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"Traps pays for itself within the first 16 months of a three-year subscription."
"They did what they said. This solution could apply to any scenario."
"The key factor that attracted me to Sophos Intercept X was the multi-platform. I have multiple clients that have mixed environments of Mac and Windows. I am able to deliver a standard solution, regardless of the platform."
"Sophos Intercept X has a host of valuable features, including its anti-malware feature, which we considered key."
"The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources."
"The client isolation feature is a very effective feature."
"There are products that are technically stronger. However, this product has everything in one solution, which makes it a strong endpoint option."
"I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures."
"Malware protection and application blocking are absolutely great. The DLP and malware features are very helpful. It is also very user-friendly, reliable, and scalable. It is easy to set up. We are also happy with its price and support."
"The security on offer is pretty good. We are happy with it."
"The most valuable use is detailing metadata collection from the endpoint and network."
"Kaspersky Anti-Targeted Attack Platform is stable and runs all the time."
"The Kaspersky Anti-Targeted Attack Platform provides visibility into telemetry data, enabling comprehensive monitoring of environmental activities."
"The solution is very easy to use. Its interface is very simple, and you can build IOC's indicators. You can use your rules to detect these attacks because you can leverage threat intelligence. Y"
"The product's deployment phase is easy."
"I feel the anti-ransomware update is one of the tool's valuable features."
"The email security feature is really good."
 

Cons

"It would be good to have a better way to search for a file within the UI."
"Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
"Additionally, I think the price is very high, and if it can be adjusted, I believe it will be a very good solution."
"The solution needs better reports. I think they should let the customer go in and customize the reports."
"However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution."
"We have found that there are times Cortex XDR by Palo Alto Networks does not detect some of the viruses, we have to use another protection solution called Kaspersky."
"It is not easy to sell Cortex XDR, not because it isn't a good tool."
"Cortex XDR could improve its sales support team, including better commission structures and referral programs."
"It would be a value-add if they can include integration with other technologies or solutions, like Fortinet, Blue Coat, etc."
"The choices offered for the on-premises and cloud-based platforms are the reverse of each other, such as the one responsible for allowing or denying access."
"They might want to offer an MSP model for licensing, to offer the solution as a software as a service."
"I would like the solution to have more functions and to be more user-friendly."
"If Sophos Intercept allows users to restrict website access based on specific needs, such as streaming new videos for business purposes, we would prefer to use that."
"Better protection in the endpoint, server, and mobile is needed."
"The after sales service and support could be improved."
"From the management side, we receive detailed information. Sophos has many features, such as Threat Hunting but that comes with the XDR version of the solution."
"The solution lacks cloud integrations."
"Kaspersky Anti-Targeted Attack Platform is not a good product. We had problems with endpoints and the solution did not detect it. We didn't get any alerts about the attack."
"The solution lacks cloud integrations."
"In some of the places I have come across, even though they use Kaspersky, the ransomware enters their system."
"The blind spot or gap in the platform is network analysis functionality."
"The backup and recovery features of the product are not good."
"I think the tool is still not really good enough for integration compared to other products."
 

Pricing and Cost Advice

"I don't recall what the cost was, but it wasn't really that expensive."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"The price was fine."
"The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help."
"Cortex XDR's pricing is ok."
"It has a yearly renewal."
"Licensing is based on the number of users. They give a discount for editors who are considered as important members. From what I know, Sophos products are not expensive. If you have a license extension, you just need to contact the editor or partner to change the mode of licensing or extend the license to cover more people."
"We are happy with the pricing across all Sophos products."
"I would rate the price 7 out of 10, where 1 is most expensive and 10 is cheapest. Also, a little reduction in price can be a great move for Intercept X Endpoint."
"The price of this solution is a little high compared to competitors because they do not have a proper pricing structure."
"It was fairly and reasonably priced."
"I have found the price of Sophos Intercept X to be reasonable."
"The pricing is actually quite reasonable."
"When you start going to the EDR technologies and the MTR, it is a little bit expensive. It's a very good technology, and obviously, you're going to pay for it, but the pricing could do a little bit of work."
"The solution has competitive pricing."
"Kaspersky Anti-Targeted Attack Platform is cheap."
"Kaspersky is one of the cheaper solutions."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
892,646 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
12%
Comms Service Provider
8%
Manufacturing Company
8%
Computer Software Company
10%
Comms Service Provider
8%
Manufacturing Company
8%
Construction Company
7%
Comms Service Provider
11%
Financial Services Firm
11%
Educational Organization
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise20
Large Enterprise48
By reviewers
Company SizeCount
Small Business75
Midsize Enterprise22
Large Enterprise22
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crodwstrike Falcon compare with Sophos Intercept X?
I like that Crowdstrike Falcon allows me to easily correlate data between my firewalls. Its detection and machine lea...
What is your experience regarding pricing and costs for Sophos Intercept X?
Intercept X Endpoint has some impact on the budget. It is quite costly when measuring Intercept X Endpoint's protecti...
What needs improvement with Kaspersky Anti-Targeted Attack Platform?
I think the tool is still not really good enough for integration compared to other products. If you need to integrate...
What advice do you have for others considering Kaspersky Anti-Targeted Attack Platform?
I recommend the tool for enterprise customers. Previously, carry, like only antivirus products, was used by many. If ...
What is your primary use case for Kaspersky Anti-Targeted Attack Platform?
I use the solution in my company since it has many good features, like sandbox features and other tech aspects. When ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Sophos Intercept X
Kaspersky Anti Targeted Attack
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Flexible Systems
Republic of Serbia, Goods.ru, Tael, Insolar
Find out what your peers are saying about Intercept X Endpoint vs. Kaspersky Anti Targeted Attack and other solutions. Updated: March 2026.
892,646 professionals have used our research since 2012.