


Find out in this report how the two AI-Powered Cybersecurity Platforms solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Threat hunting and incident summarization workflows became significantly faster during large-scale phishing or ransomware investigations, helping the team manage more incidents without increasing SOC headcount proportionally.
The summary capability saves me fifty percent of the processing time on emails.
The biggest return on investment that I've seen when using Microsoft Security Copilot is the ability to scale.
The payback period is roughly six months.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
On a scale from one to ten, I would rate customer service and technical support for Microsoft Security Copilot as a nine.
They tend to be quite rigid with documentation and often redirect me to look at documents instead of directly assisting me, which can cause delays.
Based on our customers' experiences, I would rate their support a seven out of ten.
I would rate their technical support a 10, as we have local support in South Africa and the ability to reach out to the teams quickly and effectively when they are in similar time zones, leading to great support globally.
The support is quite reliable depending on the service engineer assigned.
When I create tickets, the response is fast, and issues are solved promptly.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
We don't have any concerns whatsoever with scalability.
Scalability is the name of the game, involving understanding exactly where focus and money need to be placed and ensuring that where focus and money are placed can scale with the size, speed, and capabilities of organizations as they adopt AI in the workplace.
I think Microsoft Security Copilot scales well with the growing needs of our organization.
Vectra AI is scalable because it can work through different kinds of solutions and is compatible with all kinds of cloud solutions.
Cortex remains fast and responsive, even with increasing data and alerts.
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Cortex XDR is stable, offering high quality and reliable performance.
When talking about confidentiality, integrity, and availability, availability is the critical concern.
There are circumstances where we expected certain things to surface through our prompting with Microsoft Security Copilot, but they did not come up.
They have not had any incidents so far despite having everything on Microsoft Security Copilot.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Microsoft needs to give at least some kind of à la carte option between E3 and E5, maybe an E4, to cherry-pick from E5.
If a way could be found to make it more cost-effective and streamline the licensing mechanism, they have the technology to succeed in the marketplace.
Even though Microsoft is a major technology company with insurance coverage, customers worry about potential data leaks, especially in sensitive industries such as banking and semiconductor manufacturing.
ExtraHop's ability to decrypt encrypted data is a feature that Vectra AI lacks.
You need to have a Linux server, and from the Linux server, you must perform AI tasks, and there is a lot to be handled in the back end.
All threats, including hacking attempts, should be comprehensively addressed.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
Most of my customers are already within Microsoft stack, and the pricing is mostly well accepted.
We wanted something under one umbrella, which is something Microsoft is able to give.
Its pricing scares our customers the most.
Vectra is cheaper in terms of pricing and features compared to Darktrace.
I find the pricing of Vectra AI to be one of the best we have seen as feedback from customers and partners indicates it is very competitive for an EDR solution.
It is very acceptable when you compare it with Darktrace, for example.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
The integration of Microsoft Security Copilot with other Microsoft solutions has had a positive impact on my company's security posture because it's integrated into the operating system.
One of the major use cases that we have seen is the reduced time spent on integrating and understanding Purview's output versus Sentinel's output, because the two speak to each other through Microsoft Security Copilot.
Microsoft Security Copilot has helped us and our clients reduce the mean time to resolution significantly.
Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats.
Alert noise was dramatically reduced by nearly 80%, allowing SOC analysts to focus more on true threats, which made them more productive and resulted in higher operational efficiency.
There are extensive out-of-box detection capabilities.
| Product | Mindshare (%) |
|---|---|
| Cortex XDR by Palo Alto Networks | 11.1% |
| Vectra AI | 7.2% |
| Microsoft Security Copilot | 0.1% |
| Other | 81.6% |


| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 20 |
| Large Enterprise | 49 |
| Company Size | Count |
|---|---|
| Small Business | 6 |
| Midsize Enterprise | 6 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 10 |
| Large Enterprise | 29 |
Cortex XDR by Palo Alto Networks provides advanced threat detection with AI-driven endpoint protection and seamless integration, ensuring multi-layered security and automatic threat response.
Cortex XDR is designed to safeguard endpoints against malware and suspicious activities. It offers advanced threat detection and response capabilities using behavioral analysis, AI, and machine learning. It seamlessly integrates with security infrastructures, providing endpoint security, firewall integration, and enhanced visibility in both cloud-based and on-premises environments.
What are the key features of Cortex XDR?Organizations in diverse sectors deploy Cortex XDR to protect against malware, leveraging its advanced threat detection capabilities. Its integration with existing security infrastructures appeals to those seeking comprehensive protection in both cloud and on-premises environments, providing enhanced visibility and threat intelligence.
Microsoft Security Copilot offers innovative AI-driven security features tailored for efficient data management and protection, particularly in education and healthcare, ensuring streamlined operations and enhanced data security.
Microsoft Security Copilot enhances organizational security through its advanced features, including data sensitivity labeling and AI-driven insights, crucial for educational and healthcare sectors. Its auditing capabilities allow for efficient monitoring, while self-service analytics support active decision-making processes. With seamless integration with Microsoft platforms, it provides a synchronized ecosystem for effective data management. Improvements aim at extending capabilities across multiple systems and enhancing natural language processing to minimize prompt dependency.
What are the key features of Microsoft Security Copilot?
What benefits should organizations expect?
In the educational sector, Microsoft Security Copilot secures teacher and student data, manages incidents, and controls information access. Healthcare organizations utilize it to protect patient data, manage security incidents, and refine communication across hospitals and pharmacies. The platform's capabilities expand continually, aiding in tasks like summarizing discussions and rephrasing emails, while users explore further functions for increasing industry's operational efficiency.
Vectra AI offers advanced hybrid network and identity security, detecting threats traditional tools miss. It uses AI to identify lateral attacks and credential misuse, providing a proactive defense for enterprises.
Vectra AI enhances security by using AI-driven detection across network, cloud, and identity layers, surpassing EDR and SIEMs by offering real-time threat detection. It ensures continuous observability and automates SOC workflows to minimize manual efforts, creating an efficient security environment. Its AI-powered approach significantly reduces noise, focusing on true threats, and provides insights into complex threat landscapes, with seamless integration into environments like EDR and Office 365.
What are Vectra AI's key features?Vectra AI is utilized across industries for comprehensive network and anomaly detection. Organizations deploy it for threat hunting and incident response, monitoring both on-premises and cloud activities. By placing sensors across sites, they optimize security practices and streamline their detection processes.
We monitor all AI-Powered Cybersecurity Platforms reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.