No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks Cortex XSOAR vs SentinelOne Singularity Endpoint comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.1
Torq automation boosted efficiency, saving $600,000 annually by reducing manual tasks, with fair pricing and significant ROI.
Sentiment score
5.0
Palo Alto Networks Cortex XSOAR automates 90% of SOC tasks, enhancing efficiency and providing significant cybersecurity management value.
Sentiment score
6.0
SentinelOne Singularity Endpoint offers efficient threat detection, minimizes downtime, enhances resource efficiency, and integrates seamlessly, providing strong ROI.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
Senior Cybersecurity Engineer at a tech vendor with 10,001+ employees
By implementing Palo Alto Networks Cortex XSOAR playbooks, I automated repetitive SOC tasks such as IOC enrichment, alert triggers, host isolation, and incident ticket creation.
Cybersecurity Senior Analyst
We are positioning Palo Alto Networks Cortex XSOAR, which can be used in the SOC and do a lot of automation for the customer.
Vice President, Technology at Cache Digitech Pvt Ltd.
Palo Alto Networks Cortex XSOAR is a pure and proven technology product and cybersecurity product, customers will get more ROI when compared with others.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
SentinelOne Singularity Complete has helped reduce my organization's mean time to detect by fifty percent.
Director, Infrastructure & Security at Dreamscape Companies
If I engage five engineers for this project and implement SentinelOne, then only one resource is needed to manage the dashboard and criticality alerts.
Business Head at Ivalue Infosolution
In comparison, other EDRs such as Microsoft Defender are quite resource-hungry, and employees often complain about laptop speed, but we do not face those issues.
Cybersecurity Product Manager at a tech services company with 51-200 employees
 

Customer Service

Sentiment score
6.6
Torq's responsive 24/7 customer service is valued for quick, knowledgeable support, though some users seek advanced AI enhancements.
Sentiment score
6.5
Palo Alto Networks Cortex XSOAR support is praised for expertise and responsiveness, though some experience variability and time zone delays.
Sentiment score
7.4
SentinelOne Singularity Endpoint's support is praised for responsiveness and expertise, though access can depend on subscription and issue complexity.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Eight out of ten times, they provide valuable help.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
I would rate the customer support for Palo Alto Networks Cortex XSOAR as 9 out of 10.
Senior Cyber Defense Analyst at a manufacturing company with 10,001+ employees
Have the person that you hire know more about the product than the person on the phone.
Noc Network Engineer at a outsourcing company with 51-200 employees
If we get stuck at midnight, any other TAC team will be in GMT or Europe or America, and they will assign our support engineer and suddenly schedule a call for us and resolve the issue.
Soc Analyst at Softcell Technologies Limited
For the support team of SentinelOne Singularity Endpoint, I would rate them nine out of ten because there is a human voice there, so they are listening and responsive.
Mdr Analyst at Softcell Technologies
Most of the time, we are not aware of how to resolve those questions, and SentinelOne Singularity Endpoint's customer support helps us significantly with a prompt response.
SOC Analyst at Softcell Technologies
 

Scalability Issues

Sentiment score
6.5
Torq is praised for scalability and effectiveness, though large workflows can crash browsers, but modularization resolves it.
Sentiment score
7.0
Palo Alto Networks Cortex XSOAR is favored for scalability, seamlessly integrating tools and managing environments, despite minor integration challenges.
Sentiment score
7.8
SentinelOne Singularity Endpoint is highly scalable, effectively managing thousands of endpoints, supporting seamless growth and expansion without issues.
Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
Software Engineer at Accenture
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
The scalability of Palo Alto Networks Cortex XSOAR supports our growth and security needs because we can integrate various tools and continuously add more capability.
Enterprise Security Architect V at FirstEnergy
Palo Alto Networks Cortex XSOAR has very good application capabilities and is highly scalable.
Assistant Security Architect at Cloudnomics
The issues with scalability arise from the speed of some integrations, as not all are perfectly tuned by Palo.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
The system can scale any number of times, and only the license for each endpoint is needed.
Mdr Analyst at Softcell Technologies
I would say ten out of ten for the scalability of SentinelOne Singularity Endpoint because we can scale up and scale down as per requirement.
Security Analyst at a media company with 501-1,000 employees
The cloud-based management model makes it easier to onboard, manage, and monitor large numbers of endpoints without needing additional backend infrastructure.
Cybersecurity Engineer at Gigabit Technologies Pvt Ltd
 

Stability Issues

Sentiment score
7.4
Torq is praised for its reliability and stability, with only minor, quickly resolved issues not affecting performance.
Sentiment score
7.7
Palo Alto Networks Cortex XSOAR is stable and reliable, with minor issues often linked to plugins, updates, and configuration.
Sentiment score
8.0
SentinelOne Singularity Endpoint is highly stable, with minimal downtime and strong user satisfaction, despite occasional update connectivity issues.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular Developer at Flourish Software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
The system works smoothly even when I navigate deep into the playbook section.
Assistant Security Architect at Cloudnomics
As a leading partner, I do not anticipate any issues with stability or scalability.
Technical Consultant at Vertex Techno Solutions (B) Pvt Ltd
I would rate the stability and reliability of Palo Alto Networks Cortex XSOAR as a nine.
Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees
If I have to rate the stability level of Singularity Platform from one to ten, I would say it would be a strong nine.
Information Security Officer at a tech vendor with 51-200 employees
The automation helps a lot, and once implemented, we face no further issues regarding stability or scalability; everything works absolutely fine.
Associate Vice President at Novac Technology Solutions
Even if the agent disconnects from our console, it will still protect the desktop or laptop.
Soc Analyst at Softcell Technologies Limited
 

Room For Improvement

Torq needs better search, UI, transparency, error handling, bug fixes, AI features, templates, and case management automation integration.
Palo Alto Networks Cortex XSOAR struggles with high costs, complex deployment, and limited integrations, prompting calls for improvements.
SentinelOne Singularity Endpoint users want customizable dashboards, intuitive interfaces, better integration, less resource use, and improved support.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
The biggest area for improvement is simplifying playbook development and debugging.
Cybersecurity Senior Analyst
The deployment requires integration and the development of integration modules.
Presale Engineer at Westcon-Comstor
One of the significant issues we encounter is system slowdown when we receive an influx of alerts, which inhibits how quickly we can access the information needed for investigation.
Enterprise Security Architect V at FirstEnergy
The only thing that prevented the attack from succeeding was a free version of Malwarebytes.
Director, Information Technology at Premier Realty Group
When I find a log suspicious, if it automatically points out that a particular point in the log at a specific timing or frame is looking malicious, it would be easier for me.
Cyber Security Trainee at DataSpace Academy
SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution.
Soc Analyst at Softcell Technologies Limited
 

Setup Cost

Torq is seen as cost-effective but needs pricing transparency, with users appreciating its competitiveness compared to alternatives like Splunk.
Cortex XSOAR is costly but valued for efficiency, best suited for medium to large enterprises with dedicated security teams.
SentinelOne Singularity Endpoint offers enterprise pricing between $7 and $12 monthly, with scalable and volume-discounted licensing options.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
For customers, it is zero versus $20 million, which is why they have to make a decision.
Vice President, Technology at Cache Digitech Pvt Ltd.
Being among the market leaders, it is worth the money, though still a bit pricey.
Security Engineer at a financial services firm with 51-200 employees
The price will be high, but the solution is absolutely superb.
VP Of Digital Transformation at Netsys Solutions (Pvt) Ltd
If you want protection, you have to pay the price.
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
There are other products that are less expensive, but I tell my clients that in security, they cannot cut corners or look for the cheapest solution.
President at a tech services company with 1-10 employees
Reputation and quality are important, but especially in today’s economy, price is a significant factor.
Security and Compliance at a outsourcing company with 1,001-5,000 employees
 

Valuable Features

Torq offers AI automation, no-code interface, and strong integrations to enhance productivity, reduce workloads, and streamline security processes.
Cortex XSOAR by Palo Alto Networks enhances security operations through automation, integration, and reduced response times with advanced analytics.
SentinelOne Singularity Endpoint offers in-depth log analysis, real-time threat detection, and streamlined incident management with AI-driven capabilities.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Execution of automatic tasks for collecting, enriching, and correlating security events from hundreds of different technologies.
Presale Engineer at Westcon-Comstor
If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier.
Enterprise Security Architect V at FirstEnergy
We have implemented automation features, such as automated responses to email threats and automatic configuration of target devices for blocking specific IPs.
Vice President, Technology at Cache Digitech Pvt Ltd.
I have an advanced app providing visibility of all my endpoints, which was not the case before.
AGM IT Security at Page Industries Ltd
SentinelOne has a feature to decommission automatically, which has been fantastic.
Computer Technician at VILLE DE POINTE-CLAIRE
There's also automation that gives my team free time, preventing them from having to look for every alert.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
17
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (4th), AI-SOC (1st), AI-Powered Security Automation (1st)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
62
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (2nd), SOC as a Service (2nd)
SentinelOne Singularity End...
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
275
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Anti-Malware Tools (2nd), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), AI-Powered Cybersecurity Platforms (2nd), AI Observability (2nd)
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks Cortex XSOAR8.9%
Microsoft Sentinel9.3%
Splunk SOAR7.1%
Other74.69999999999999%
Security Orchestration Automation and Response (SOAR)
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint5.3%
CrowdStrike Falcon7.2%
Microsoft Defender for Endpoint5.6%
Other81.9%
Endpoint Detection and Response (EDR)
 

Featured Reviews

AD
Solutions Architect at ProArch
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
EricRise - PeerSpot reviewer
Noc Network Engineer at a outsourcing company with 51-200 employees
Automation playbooks have reduced soc noise and now streamline daily incident response
To improve Palo Alto Networks Cortex XSOAR, there can be a learning curve to it. It is not a very user-friendly product; it is complex. It handles debugs and automation playbooks. You have to really spend some time dedicated to learning the product, scripting, and acquiring your certifications on it. Cost is another item as well. That can be quite significant; it does depend on other tools for EDR, whether you are using Palo Alto's XDR system or any number of third-party products for that. There are some reporting and logging restrictions and limitations. Some of those are going to be constraints, including window size limits. Database use with it has limited scalability for that type of application.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
909,701 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Construction Company
10%
Outsourcing Company
10%
Comms Service Provider
9%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Government
6%
Outsourcing Company
9%
Manufacturing Company
9%
Computer Software Company
9%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise5
Large Enterprise10
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise9
Large Enterprise32
By reviewers
Company SizeCount
Small Business134
Midsize Enterprise71
Large Enterprise93
 

Questions from the Community

What needs improvement with Torq?
Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I...
What is your primary use case for Torq?
My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take ...
What advice do you have for others considering Torq?
I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
My experience with pricing, setup cost, and licensing for Palo Alto Networks Cortex XSOAR is that I was just a consum...
What needs improvement with Palo Alto Networks Cortex XSOAR?
Palo Alto Networks Cortex XSOAR can be improved if it can include AI modules within Palo Alto Networks Cortex XSOAR a...
What is your primary use case for Palo Alto Networks Cortex XSOAR?
My main use case for Palo Alto Networks Cortex XSOAR is that we use it as a SOAR platform, Security Orchestration and...
Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the p...
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
Sentinel Labs, SentinelOne Singularity, Singularity Platform
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about Splunk, Palo Alto Networks, Microsoft and others in Security Orchestration Automation and Response (SOAR). Updated: July 2026.
909,701 professionals have used our research since 2012.