Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Cortex XSOAR vs ThreatConnect Threat Intelligence Platform (TIP) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palo Alto Networks Cortex X...
Ranking in Security Orchestration Automation and Response (SOAR)
3rd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
49
Ranking in other categories
SOC as a Service (2nd)
ThreatConnect Threat Intell...
Ranking in Security Orchestration Automation and Response (SOAR)
15th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
8
Ranking in other categories
Threat Intelligence Platforms (TIP) (6th)
 

Mindshare comparison

As of December 2025, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Palo Alto Networks Cortex XSOAR is 9.4%, down from 11.5% compared to the previous year. The mindshare of ThreatConnect Threat Intelligence Platform (TIP) is 2.4%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR9.4%
ThreatConnect Threat Intelligence Platform (TIP)2.4%
Other88.2%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

CC
Enterprise Security Architect V at FirstEnergy
Customization supports seamless workflow while data influx challenges response time
What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali. I can create various custom automations and custom fields. There is significant customization ability in this platform. If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier. All of our alerts from different tools come into this central place as we have multiple SIEMs. We have items coming from Anomali and other platforms that are not SIEM tools. This serves as our central location where our SOC analysts can work and determine if incident response is needed. The platform provides data enrichment capabilities, offering information upfront so analysts do not have to search for it. They can access details such as username, phone number, email address, and workplace information. For malware files, they can retrieve details from VirusTotal, including file names and environment presence. We have built substantial automation around these features, which also helps us track case metrics, investigation time, and threat mitigation duration.
Zaid bin junaid  - PeerSpot reviewer
Growth and Product Manager at Flash.co
Detects cyber threats early and improves incident response with AI-driven insights
The main focus for using ThreatConnect Threat Intelligence Platform (TIP) is advanced threat prediction and data protection of the organization, which has a great response to threat detection. If there is a cyber security attack, it helps significantly. The platform is exceptionally efficient and provides a very good response whenever required. The advanced threat detection helps identify suspicious activity, and whenever there is a cyber attack, it focuses on the process, analyzes the cyber security attacks on time, and provides advance warning if there is a problem. The artificial intelligence used is something relied upon and is truly excellent. Key features of ThreatConnect Threat Intelligence Platform (TIP) include a Unified Threat Library that centralizes the threat intelligence data sources and normalizes the scoring data to ensure that it is ready for action. It also provides AI-powered analytics that uses AI-driven tools like CAL and ATT&CK analysis to provide insights and contextualize the threats and behaviors. The Unified Library helps unify the data, enables advanced detection, and provides centralized analysis of the threat library, connecting to ongoing or incoming threats. It helps with strategic, tactical, operational, and technical threat intelligence, with each type providing a different insight into the threat landscape, contributing to a well-rounded cyber security strategy. It has helped create a more secure environment, improving scalability and work efficiency by 38.5%. It has also helped defend against multiple cyber attacks, making it a truly beneficial solution.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XSOAR's most valuable features are the playbooks, custom integration, the machine-learning model, and the layout, classifier, and mapper."
"The automation part and the playbook creation part are awesome. The way it is responding to the customers and incidents is also very good. In the SOC environment, I guess it will carry out around 50% of the work."
"The product is quite easy to use."
"It’s easy to install."
"The pricing is very good."
"It is a scalable solution."
"The solution is easy to deploy."
"It has an extensive list of integrations that are available out of the box which makes it easy to start."
"I like their customer support."
"The most valuable features are ease of use and the ability to customize it."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"We have been able to see a return on investment as our clients believe in us more."
"ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls."
"The tool's installation, integration, and playbooks are very straightforward."
"The product automatically generated a threat score based on the maliciousness of an IP."
"ThreatConnect Threat Intelligence Platform (TIP) is a robust platform that helps with advanced AI-driven intelligence, and it assists whenever there is a problem, serving as a single-stop solution."
 

Cons

"The platform’s setup procedures could be streamlined compared to one of its competitors."
"The dashboard could be better."
"I would love to see more flexibility on what we can display and design on the dashboards."
"Implementing this solution requires a lot of involvement from the vendor and it should be made easier for the partners."
"The integration could be better. Cortex, for example, does not work with iPhone."
"It is not a very scalable solution."
"Creating complex playbooks using coding languages, such as Python, could be easier."
"Palo Alto Networks Cortex XSOAR lacks to offer SIEM functionalities currently."
"I couldn’t get any training videos online when I was working with the tool."
"Integration is an area that could use some improvement."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
"I would like to see improvements in the time zone support of their customer service, considering users are from different time zones."
"They should make it a little bit easier to generate events and share them with the community"
"ThreatConnect Threat Intelligence Platform (TIP) could be better in terms of cost, as the basic needs of the software are emphasized."
"It would be good to have more feeds and more integrated sources for enrichment."
"ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic."
 

Pricing and Cost Advice

"The solution is a bit on the expensive side."
"It's cheaper compared to its competitors."
"The solution is based on an annual licensing model that is expensive."
"There is a perception that it is priced very high compared to other solutions."
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"The solution's pricing needs improvement."
"Palo Alto offers significant discounts to customers who purchase the products repeatedly."
"The solution's cost is high."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"The price could be better."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"The tool is expensive."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
879,310 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
Financial Services Firm
17%
Computer Software Company
7%
Comms Service Provider
6%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise23
Large Enterprise4
 

Questions from the Community

What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is zero versus $20 million, which is why they have to make a decision.
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. We need to see improvements in that area to facilitate cyber analysts.
What is your experience regarding pricing and costs for ThreatConnect Threat Intelligence Platform (TIP)?
The experience with pricing, setup cost, and licensing was seamless. Assistance was provided with everything on time, but the pricing could be improved as it is somewhat pricey compared to other so...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) could be better in terms of cost, as the basic needs of the software are emphasized. It provides good solutions, but if similar offerings were avail...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
The main use case is threat detection, and it helps day-to-day with threat detection, response, and the cyber security automation feature, which is exceptionally effective. ThreatConnect Threat Int...
 

Also Known As

Demisto Enterprise, Cortex XSOAR, Demisto
No data available
 

Interactive Demo

 

Overview

 

Sample Customers

Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Customer Case Studies & Use Cases
Find out what your peers are saying about Palo Alto Networks Cortex XSOAR vs. ThreatConnect Threat Intelligence Platform (TIP) and other solutions. Updated: December 2025.
879,310 professionals have used our research since 2012.