No more typing reviews! Try our Samantha, our new voice AI agent.

Intercept X Endpoint vs Tanium comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Intercept X Endpoint
Ranking in Endpoint Protection Platform (EPP)
15th
Ranking in Endpoint Detection and Response (EDR)
17th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
ZTNA (13th), Managed Detection and Response (MDR) (13th), Extended Detection and Response (XDR) (16th), Ransomware Protection (3rd)
Tanium
Ranking in Endpoint Protection Platform (EPP)
14th
Ranking in Endpoint Detection and Response (EDR)
23rd
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
23
Ranking in other categories
Vulnerability Management (24th), Unified Endpoint Management (UEM) (8th), Autonomous Endpoint Management (3rd)
 

Mindshare comparison

As of August 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.9%, up from 3.7% compared to the previous year. The mindshare of Intercept X Endpoint is 1.8%, up from 1.5% compared to the previous year. The mindshare of Tanium is 2.5%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.9%
Tanium2.5%
Intercept X Endpoint1.8%
Other91.8%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
AM
IT Head at Dee Development
Has struggled to detect major threats but has offered basic protection over time
Intercept X Endpoint could learn from CrowdStrike in terms of overall performance and filtering because performance is most important, especially these days as Windows is getting buggier and buggier, which puts a huge load on the PC, and even with the most advanced CPUs and everything in place, it still lags in performance in so many places, thanks to Windows' clumsy design of these collaboration suites that make it extremely heavy on PC's resources. The interface of Intercept X Endpoint is quite old-fashioned. The Sophos interfaces, including for Intercept X Endpoint, are quite bad actually; to be very honest, even in UTM boxes, they are not great at all. You can hardly see a very small portion of windows while it's creating the firewall rules, and we have been complaining about this for quite some time, but there hasn't been any improvement on those grounds. Intercept X Endpoint's anti-ransomware capabilities failed us during a bad attack, and just because of our own backup policies, we could restore our normal operations; otherwise, if we had to depend on this solution, we would have been long dead because the infection was so bad, it couldn't even detect the infection. Intercept X Endpoint cannot handle zero-day attacks; in my experience, last year, we had this major issue with a malware attack, and it happened just because of our backup policies that we were able to recover without any support from Sophos, which just told us they would charge us some 1 Crore in rupees. Intercept X Endpoint should improve their implementation; things will never be perfect for the new world. This new world is always facing new kinds of attacks and new ways to compromise the system. They need to learn fast, implement fast, and sometimes redesigning the solution is the solution—not just patchwork. There was a time we used to love Sophos because of its fresh design and innovative thought. In my experience, when technical companies are led by MBA professionals, they lose their shine on the technical part and become more dependent on target sales; it turns into a marketing-centric operation that loses the technical focus completely.
Sandeepraj Gatla - PeerSpot reviewer
Dfir Analyst at a tech services company with 201-500 employees
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use. We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5. Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have found in our test Cortex XDR by Palo Alto Networks to be a very good tool."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"It is easy to use."
"Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
"The user interface of the solution is sophisticated and straightforward."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"I like the centralized console and the predictive analysis it does of malware. It is very stable and also scalable."
"Traps pays for itself within the first 16 months of a three-year subscription."
"The effectiveness of Intercept X Endpoint's deep learning technology in threat detection helps my team and my customers through automated incident response features."
"This is really good because it's applicable to zero-day threats."
"The thing that I like about it is the synchronized security. You can tie endpoint protection and firewalls and a whole range of other services and products. You can get your servers taken in under this."
"The EDR (Enhanced Data Detection and Response) and the DLP (Data Loss Prevention) components are valuable assets."
"After that, the client switched to Sophos to get the protection they lacked. It either works or it doesn’t and Sophos works."
"Scalability is good."
"We find all features valuable."
"Intercept X Endpoint has been stable, and I appreciate the centralized management and the reporting feature."
"I like the tool's incident response and security patching."
"Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint."
"I would say Tanium is the best tool for vulnerability management."
"The insights we gain from our endpoints and the management capabilities that Tanium provides have been a boon to our operations and security."
"Tanium is a very good product and I would rate it eight or nine out of ten."
"The security features are very valuable."
"It's definitely not complex, it is pretty user-friendly and it's a solid tool enterprise to use."
"For inventory purposes, it's from one of the best things on the scene, as you can get live inventory."
 

Cons

"The technical support is not very good. I find the process difficult."
"We would also like to have advanced tech protection and email scanning."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"They have the worst support, as a company, that I have ever worked with, as they are difficult to get a hold of and keep on the phone. They don't know what they are talking about when you get them on the phone. They don't like to respond to messages when you send them to them. They like to "research problems" for weeks on end, then pass you off to somebody else."
"Enhancing UI simplicity and playbook flexibility are areas that could benefit from more low-code automation options for smoother integrations."
"If they had pulse rate detection, it would be better."
"There's room for improvement with Mac device installations, which can be challenging."
"It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
"We are not able to merge the sub-estates. If we create multiple sub-states and there may be instances where a user is in a different sub-state, it may not be possible for us to relocate that user from one sub-state to another through the console. We have to merge them manually which is not ideal."
"When we load Intercept X, it puts a load on the device. When it is scanning, it slows down the device. A system with basic specifications completely slows down till the scan is complete. They should improve this part."
"The detection and the AI capabilities should be improved upon."
"It would be beneficial if you could expand support for Windows 7 and Windows Server 2008 without charging an additional fee."
"The initial setup was not very user-friendly, but it improved during the evolution."
"This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it."
"The support needs improvement."
"Sophos Intercept X could improve on its setup process. They could make it easier to have a baseline set up for the system, or at least provide more understanding of what the baseline is when you first install it. This could be a matter of lack of training on my part, but it's difficult to receive training on solutions that are not Cisco. Cisco is the only vendor with classes or courses."
"The problem or challenge is a pre-sales and go-to strategy for the SMB market delivered through a channel or model. It's very convoluted and vague, which leads to some confusion about the various types of modules, and the device-to-seat cost is extremely difficult to calculate."
"We set a policy to block USB access. The moment a device is being set up on the network, I apply the policy, but it does not come into effect immediately."
"When working with Tanium, there are some older devices that haven't been patched for a long time, and certain patches are not included in Tanium. I have to search outside to download patches, create bundles, and then perform the task."
"Our biggest issue with the solution is its lack of mobility."
"The performance could improve in future releases. We have had performance issues in specialized web environments, but overall I think the problems are less than 2% of the computer systems being used."
"The solution lacks mobility."
"The solution can give a lot of false positives."
"Tanium’s scalability could be improved."
 

Pricing and Cost Advice

"It has a yearly renewal."
"The price of the product is not very economical."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"The solution is expensive. It's pricing is on a yearly-basis."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"I am using the Community edition."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help."
"The price of this solution is a little high compared to competitors because they do not have a proper pricing structure."
"As I am not responsible for paying the bills I cannot comment on the pricing."
"There is a license required to use this solution."
"On a per-user basis, my company has to pay a certain amount of money."
"The solution is not expensive."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing ten out of ten."
"When you start going to the EDR technologies and the MTR, it is a little bit expensive. It's a very good technology, and obviously, you're going to pay for it, but the pricing could do a little bit of work."
"I am not sure about the cost. I would guess it to be between $50 to $60 per license. This would be the cost of the overall subscription. There is no additional fee."
"It's an expensive solution. It would be nice if the cost were lower."
"It is higher than some competitors in the market."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"There is an annual license required to use this solution."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"The solution is expensive but it's a good investment."
"The solution offers value for money."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
908,877 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Construction Company
10%
Comms Service Provider
9%
Outsourcing Company
9%
Manufacturing Company
8%
Financial Services Firm
14%
Government
10%
Manufacturing Company
9%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business76
Midsize Enterprise21
Large Enterprise22
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise12
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crodwstrike Falcon compare with Sophos Intercept X?
I like that Crowdstrike Falcon allows me to easily correlate data between my firewalls. Its detection and machine lea...
What is your experience regarding pricing and costs for Sophos Intercept X?
Intercept X Endpoint has some impact on the budget. It is quite costly when measuring Intercept X Endpoint's protecti...
What needs improvement with Sophos Intercept X?
Intercept X Endpoint can be improved in several ways. Currently, it is only available on the cloud, and having it ava...
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Sophos Intercept X
Tanium Inc Cloud, Tanium XEM
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Flexible Systems
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about Intercept X Endpoint vs. Tanium and other solutions. Updated: August 2026.
908,877 professionals have used our research since 2012.