No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks Cortex XSOAR vs Proofpoint Threat Response comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.9
Torq automation boosts workflow efficiency and ROI by reducing alert handling time, saving hours daily, and offering fair pricing.
Sentiment score
4.9
Cortex XSOAR enhances ROI by automating SOC tasks, reducing manual effort, increasing efficiency, and decreasing response times.
Sentiment score
8.3
Proofpoint Threat Response boosts ROI, saves time, cuts costs, and improves efficiency and satisfaction for management and the SOC team.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
Senior Cybersecurity Engineer at a tech vendor with 10,001+ employees
By implementing Palo Alto Networks Cortex XSOAR playbooks, I automated repetitive SOC tasks such as IOC enrichment, alert triggers, host isolation, and incident ticket creation.
Cybersecurity Senior Analyst
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Vice President, Technology at Cache Digitech Pvt Ltd.
Palo Alto Networks Cortex XSOAR is a pure and proven technology product and cybersecurity product, customers will get more ROI when compared with others.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
Now, it is all taken care of by Proofpoint with zero human error, allowing hours of work to be completed in minutes.
Assistant Consultant at a tech services company with 11-50 employees
 

Customer Service

Sentiment score
6.6
Torq's customer service is praised for 24/7 support, helpful documentation, quick responses, and knowledgeable staff.
Sentiment score
6.6
Cortex XSOAR support is responsive and knowledgeable, but some users face delays and service quality issues without premium support.
Sentiment score
9.7
Proofpoint offers responsive, professional customer service with effective support and documentation, ensuring user satisfaction and high-quality assistance.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Eight out of ten times, they provide valuable help.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
I would rate the customer support for Palo Alto Networks Cortex XSOAR as 9 out of 10.
Senior Cyber Defense Analyst at a manufacturing company with 10,001+ employees
Their support has been better than Anomali's and they are more responsive.
Enterprise Security Architect V at FirstEnergy
I would rate customer support a ten because they are prompt with solutions, provide advice during troubleshooting, and their documentation is excellent.
Assistant Consultant at a tech services company with 11-50 employees
 

Scalability Issues

Sentiment score
6.5
Torq is praised for scalability and efficient cloud-native architecture, though large workflows can hinder performance without modularization.
Sentiment score
7.0
Palo Alto Networks Cortex XSOAR is highly scalable, integrating seamlessly with third-party APIs and supporting diverse tools effectively.
Sentiment score
6.8
Proofpoint Threat Response scalability is mixed, dependent on hardware and integrations, with potential for improvement, especially in cloud deployment.
Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
Software Engineer at Accenture
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Enterprise Security Architect V at FirstEnergy
Palo Alto Networks Cortex XSOAR has very good application capabilities and is highly scalable.
Assistant Security Architect at Cloudnomics
The issues with scalability arise from the speed of some integrations, as not all are perfectly tuned by Palo.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Scalability is currently limited, as it only integrates with Proofpoint Email Protection, Proofpoint TAP, and the Abuse Mailbox.
Assistant Consultant at a tech services company with 11-50 employees
 

Stability Issues

Sentiment score
7.5
Torq is favored for its reliable uptime and stable performance, with minor issues resolved swiftly and effectively.
Sentiment score
7.7
Palo Alto Networks Cortex XSOAR is stable, reliable, often rated highly, with manageable bugs, especially when cloud-hosted.
Sentiment score
8.1
Proofpoint Threat Response is praised for robust stability, though some users cite database-related scalability issues in large deployments.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular Developer at Flourish Software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
The system works smoothly even when I navigate deep into the playbook section.
Assistant Security Architect at Cloudnomics
As a leading partner, I do not anticipate any issues with stability or scalability.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
I would rate the stability and reliability of Palo Alto Networks Cortex XSOAR as a nine.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
 

Room For Improvement

Torq needs AI enhancements, improved integration visibility, and comprehensive user support to optimize automation workflows and connectivity.
Cortex XSOAR needs improved documentation, UI, integration speed, and customization; users want easier setup, better support, and advanced features.
Enhancing support, integration, and interface design, while considering scalability and user interaction improvements, would benefit Proofpoint Threat Response.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
The biggest area for improvement is simplifying playbook development and debugging.
Cybersecurity Senior Analyst
The deployment requires integration and the development of integration modules.
Presale Engineer at Westcon-Comstor
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Enterprise Security Architect V at FirstEnergy
I suggest adding support for other email protection services such as Cisco IronPort, IronMail, and Abnormal, which would enhance its capabilities.
Assistant Consultant at a tech services company with 11-50 employees
 

Setup Cost

Enterprise buyers find Torq's pricing competitive and valuable, with many renewing annually due to satisfied experiences.
Palo Alto Networks Cortex XSOAR is costly but valued for efficiency and comprehensive security event management, with potential discounts.
Proofpoint Threat Response is considered cost-effective with good value and relatively low cost compared to alternatives like Abnormal Security.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
For customers, it is zero versus $20 million, which is why they have to make a decision.
Vice President, Technology at Cache Digitech Pvt Ltd.
Being among the market leaders, it is worth the money, though still a bit pricey.
Security Engineer at a financial services firm with 51-200 employees
The price will be high, but the solution is absolutely superb.
VP Of Digital Transformation at Netsys Solutions (Pvt) Ltd
For pricing, setup cost, and licensing, it is necessary to purchase Proofpoint professional services if assistance is desired during setup, which is quite easy.
Assistant Consultant at a tech services company with 11-50 employees
 

Valuable Features

Torq enhances productivity and satisfaction with integration, no-code automation, AI assistance, and a unified, error-reducing platform.
Cortex XSOAR excels in automation, playbooks, and integrations, enhancing incident management and collaboration for security teams.
Proofpoint Threat Response enhances email security with auto-pulling, phishing protection, integration, and efficient spam and false positive management.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Presale Engineer at Westcon-Comstor
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
Enterprise Security Architect V at FirstEnergy
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Vice President, Technology at Cache Digitech Pvt Ltd.
Proofpoint Threat Response has positively impacted the organization by improving security posture, providing breathing space for the SOC team with fewer false positives, and offering a tool for users to report any malicious email using the Abuse Mailbox, which the SOC team can analyze.
Assistant Consultant at a tech services company with 11-50 employees
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.8
Reviews Sentiment
6.6
Number of Reviews
16
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (4th), AI-SOC (1st), AI-Powered Security Automation (1st)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
61
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
Proofpoint Threat Response
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
6
Ranking in other categories
Security Incident Response (4th)
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR8.9%
Microsoft Sentinel9.3%
Splunk SOAR7.1%
Other74.69999999999999%
Security Orchestration Automation and Response (SOAR)
Security Incident Response Mindshare Distribution
ProductMindshare (%)
Proofpoint Threat Response6.1%
VMware Carbon Black Cloud9.2%
ServiceNow Security Operations8.8%
Other75.9%
Security Incident Response
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
Sricharan R - PeerSpot reviewer
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
Security automation has transformed incident workflows and now reduces response time dramatically
I think the areas of Palo Alto Networks Cortex XSOAR that could be improved are mainly in UX. We have communicated with the vendor team about this, but they are prioritizing product functionality over usability because most target customers are technical and understand a primitive UI. They face difficulties in implementing UI changes as their team is stretched. Thus, the UI/UX of the tool needs significant improvement. There are plans on their roadmap, but a lot remains to be done. Parts of the tool run on an older framework, causing slowness. Usability is a broader issue than features alone. This usability problem is common in many cybersecurity tools, unlike customer-facing applications. Some integrations have speed issues and might not function seamlessly with different upstream configurations, requiring manual updates. These are the main pain points we encountered, particularly with UI/UX, integration speed, and the usability of certain inbuilt playbooks.
reviewer2839371 - PeerSpot reviewer
Assistant Consultant at a tech services company with 11-50 employees
Automated email removal has reduced spam impact and gives the security team more time for analysis
Proofpoint Threat Response offers the best features through creating a workflow that deals with different types of emails, including identifying spam. If any user identifies an email as malicious, it triggers a workflow to the information security team, who will analyze it and determine whether to inform the user that it is not malicious or trigger a flow. A flow can be created for different types, where high spam emails are auto-pulled, low spam emails are quarantined for analysis, and integration with Proofpoint TRAP and Proofpoint TAP allows auto-pull for emails declared malicious. Additionally, I can revert changes if an email initially declared as spam is later found not to be spam, restoring it to the user's mailbox without user intervention. This complete feature encompasses threat response, prediction, activations, deletions, and sometimes restorations. I find myself using the integration with TAP and the integration with the Abuse Mailbox the most because those are utilized daily. Users often confuse whether an email is malicious or not, prompting them to use Proofpoint Abuse Mailbox via the report phishing button. As spammers grow more intelligent, Proofpoint TAP is also useful by flagging those emails. No action is required on our side because it is the collaboration between Proofpoint Threat Response and Targeted Attack Protection, making the SOC team's work easier, with reduced false positives, allowing them time for more productive tasks. Proofpoint Threat Response has positively impacted the organization by improving security posture, providing breathing space for the SOC team with fewer false positives, and offering a tool for users to report any malicious email using the Abuse Mailbox, which the SOC team can analyze. Proofpoint intelligence can then declare emails malicious or not and pull them from the user's mailbox. The solution has impacted us positively, safeguarding against spam while giving the SOC team the capacity to analyze needs without being overwhelmed by false positives. In previous days without Proofpoint Threat Response Auto-Pull, the SOC team spent more than two or three hours analyzing emails, checking hash values, verifying the nature of emails, and conducting eDiscovery for malicious emails. During mass spam attacks, the entire day was consumed in firefighting mode. Now, with Proofpoint Threat Response Auto-Pull, integration with TAP, Abuse Mailbox, CSV integration, and other data sources, the team can perform tasks that once required hours in just a minute.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Construction Company
10%
Outsourcing Company
10%
Comms Service Provider
9%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Government
6%
Financial Services Firm
15%
Comms Service Provider
12%
University
10%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise5
Large Enterprise9
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise9
Large Enterprise32
No data available
 

Questions from the Community

What needs improvement with Torq?
The only thing is more out-of-the-box integrations. Torq already has a lot of supported integrations and adding new o...
What is your primary use case for Torq?
For Torq, first of all, it's a hyperautomation and AI assistant usage. Our EDR SentinelOne is integrated in Torq and ...
What advice do you have for others considering Torq?
I think I have told everything about Torq that I can share at this stage, but I am still in the process of learning t...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
My experience with pricing, setup cost, and licensing for Palo Alto Networks Cortex XSOAR is that I was just a consum...
What needs improvement with Palo Alto Networks Cortex XSOAR?
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR a...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My main use case for Palo Alto Networks Cortex XSOAR is that we use it as a SOAR platform, Security Orchestration and...
What is your experience regarding pricing and costs for Proofpoint Threat Response?
For pricing, setup cost, and licensing, it is necessary to purchase Proofpoint professional services if assistance is...
What needs improvement with Proofpoint Threat Response?
To improve Proofpoint Threat Response, I suggest adding support for other email protection services such as Cisco Iro...
What is your primary use case for Proofpoint Threat Response?
Proofpoint Threat Response was initially implemented on-premises as Proofpoint Threat Response Auto-Pull, integrated ...
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
No data available
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
University of Waterloo, Akorn, Fenwick and West LLP
Find out what your peers are saying about Splunk, Palo Alto Networks, Microsoft and others in Security Orchestration Automation and Response (SOAR). Updated: July 2026.
908,800 professionals have used our research since 2012.