Try our new research platform with insights from 80,000+ expert users

Palo Alto Networks Cortex XSOAR vs Trellix Helix Connect comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Torq
Sponsored
Average Rating
8.0
Reviews Sentiment
2.2
Number of Reviews
1
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (8th), AI-SOC (13th), AI-Powered Security Automation (2nd)
Palo Alto Networks Cortex X...
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
49
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd), SOC as a Service (2nd)
Trellix Helix Connect
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
13
Ranking in other categories
Security Information and Event Management (SIEM) (19th), Security Incident Response (3rd)
 

Mindshare comparison

Security Orchestration Automation and Response (SOAR) Market Share Distribution
ProductMarket Share (%)
Palo Alto Networks Cortex XSOAR8.9%
Microsoft Sentinel13.0%
Splunk SOAR7.8%
Other70.3%
Security Orchestration Automation and Response (SOAR)
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Trellix Helix Connect1.0%
Splunk Enterprise Security7.4%
Wazuh7.3%
Other84.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2767650 - PeerSpot reviewer
Senior Consultant at a university with 10,001+ employees
Have found automation to save analyst time but miss more accurate data classification
From our research and testing with the tool, we determined there need to be modifications and changes to train the LLM on the back end. It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet. It was unable to do that sort of classification. We concluded this tool would be more suitable for initial ticket management rather than security automation. Regarding data handling, I would give preference to Torq. For case management, Cortex and its dashboards prove more useful. Cortex and Palo's solutions do not have as much capability as Torq provides with the same tools. However, Torq's dashboards could be improved, especially on the case management side.
CC
Enterprise Security Architect V at FirstEnergy
Customization supports seamless workflow while data influx challenges response time
What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali. I can create various custom automations and custom fields. There is significant customization ability in this platform. If I already have an established process, I do not have to change my process to fit into the tool. I can modify the tool to fit into my process, which makes things considerably easier. All of our alerts from different tools come into this central place as we have multiple SIEMs. We have items coming from Anomali and other platforms that are not SIEM tools. This serves as our central location where our SOC analysts can work and determine if incident response is needed. The platform provides data enrichment capabilities, offering information upfront so analysts do not have to search for it. They can access details such as username, phone number, email address, and workplace information. For malware files, they can retrieve details from VirusTotal, including file names and environment presence. We have built substantial automation around these features, which also helps us track case metrics, investigation time, and threat mitigation duration.
reviewer2646834 - PeerSpot reviewer
Presales Lead at a outsourcing company with 11-50 employees
Reduces detection and response times through automation and alert correlation
The best features that Trellix Helix Connect offers are SOAR, automation, hyperautomation, and the correlation of alerts and threat intelligence, for example, when the alerts cross through MITRE ATT&CK, which stand out most to me. Out of those features, automation, alert correlation, and threat intelligence have made my work easier and more effective as we integrate many cybersecurity solutions into the XDR and set up the use cases to reduce MTTD and MTTR from days to minutes. I would add that the level of integration with other brands is something that surprises me about the features of Trellix Helix Connect. Trellix Helix Connect has positively impacted my organization as it is the most important tool to provide MDR service to our clients, which has resulted in specific outcomes and improvements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"As an analyst, it has demonstrated potential to reduce workforce requirements and time needed for related activities."
"For organizations that are stable with their security operations, like those with around 50 members in their security team running full-phased operations 24/7, Cortex is necessary."
"The most valuable features of Cortex XSOAR include its vast library of plugins, which allow us to integrate various tools and solutions seamlessly."
"Its agility and scalability are valuable."
"What I appreciate most about Palo Alto Networks Cortex XSOAR is that it is very open, even more so than Anomali."
"It has an extensive list of integrations that are available out of the box which makes it easy to start."
"The orchestration in XSOAR is significantly easier compared to other SOAR tools I've used."
"It was easy to integrate Cortex with existing infrastructure and other tech tools."
"The product is quite easy to use."
"I advise other customers to choose Trellix Helix, as it improves operations significantly with more efficient responses required for various scenarios they face."
"The most valuable features include predefined use cases and threatening states."
"As far as its core functionality goes, it’s spot-on."
"The best feature of Trellix Helix Connect is its quick implementation."
"Trellix Helix helps prevent email attacks, like phishing and email spoofing attacks."
"The product offers very strong automation. Our cyber security analysts don't have to correlate the information to detect problems. They only need to analyze problems that have been identified by the platform."
"FireEye Helix's best features are its speed and use of an easy-to-understand language to send queries to the raw logs."
"We have started working with various customers, one of whom is particularly concerned about adjacency. We have identified several use cases where automation is possible."
 

Cons

"It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet."
"The solution's technical support could be better."
"The price of the solution could be improved."
"Palo Alto needs to develop more AI-centric products."
"Creating complex playbooks using coding languages, such as Python, could be easier."
"I would love to see more flexibility on what we can display and design on the dashboards."
"They should provide integration with machine learning platforms."
"Palo Alto Networks Cortex XSOAR could improve the look, feel, and management of the cloud console. Additionally, the user could be more easily integrated."
"The dashboard could be better."
"Trellix needs to address the price for the product to be more appealing to customers."
"I think the usability of hyperautomation is something to improve in the solution because it is expensive regarding the needed improvements."
"FireEye Helix would be improved with the option of an on-prem version, which they don't currently offer."
"Integrations could be improved, and the dashboard could be a little better."
"Trellix Helix's configuration and learning could be improved to identify normal traffic from abnormal and to identify trusted domains."
"While we have top customer support and this solution is highly beneficial, there is room for improvement due to the fusion of McAfee and FireEye, which has caused some lapses in support."
"It should have more cloud connectors. It could also be cheaper."
"We have certain challenges with integrating the SOAR platform with multiple vendors."
 

Pricing and Cost Advice

Information not available
"The price of Palo Alto Networks Cortex XSOAR is comparable to other solutions in the market."
"It is approx $10,000 or $20,000 per year for two user licenses."
"The price of Palo Alto Networks Cortex XSOAR is expensive."
"When I first looked at Demisto, it had a price tag of $250,000 but when we finally purchased it, it was $345,000."
"It's cheaper compared to its competitors."
"The solution's cost is reasonable."
"Cortex XSOAR's price could be lower."
"It is expensive."
"The price could be better. But I think it's rightly placed when we buy everything in one shot, and we get some discount for that. That's how we basically plan our deployment, and it's holistic. We pay for the license yearly."
"It could be cheaper, but that applies to every product."
"I rate Trellix Helix a five out of ten for pricing."
"FireEye Helix is a little expensive."
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
879,889 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
9%
Manufacturing Company
7%
Healthcare Company
6%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
Comms Service Provider
16%
Computer Software Company
11%
Manufacturing Company
10%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business19
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise7
 

Questions from the Community

What needs improvement with Torq?
From our research and testing with the tool, we determined there need to be modifications and changes to train the LL...
What is your primary use case for Torq?
I used Torq for conducting one of the proof of evaluations for a vendor we are connected with. I am currently working...
What advice do you have for others considering Torq?
One of our members uses AWS, and we receive their feed. This involves triaging AWS-related logs. While I do not have ...
What is your experience regarding pricing and costs for Palo Alto Networks Cortex XSOAR?
Comparing pricing to Micro Focus, they were offering bundles, making it free with their SIEM. For customers, it is ze...
What needs improvement with Palo Alto Networks Cortex XSOAR?
To improve the solution, it needs to have complete features that are low-code, no-code, and should be plug-and-play. ...
What is your experience regarding pricing and costs for FireEye Helix?
The price of Trellix Helix is competitive in the market. It is not the cheapest but also not the most expensive. As f...
What needs improvement with FireEye Helix?
To improve Trellix Helix Connect, I think it is possible to enhance the dashboard to share more information about the...
What is your primary use case for FireEye Helix?
My main use case for Trellix Helix Connect is to provide an MDR service to our clients. We use Trellix Helix Connect ...
 

Also Known As

No data available
Demisto Enterprise, Cortex XSOAR, Demisto
FireEye Helix, FireEye Threat Analytics
 

Overview

 

Sample Customers

Information Not Available
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
Police Bank, Verisk Analytics, Teck Resources
Find out what your peers are saying about Microsoft, Splunk, Palo Alto Networks and others in Security Orchestration Automation and Response (SOAR). Updated: December 2025.
879,889 professionals have used our research since 2012.