No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 InsightIDR vs WatchGuard EPDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
34th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (19th)
WatchGuard EPDR
Ranking in Endpoint Detection and Response (EDR)
22nd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Protection Platform (EPP) (16th)
 

Mindshare comparison

As of August 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.7%, down from 3.8% compared to the previous year. The mindshare of Rapid7 InsightIDR is 1.3%, up from 1.1% compared to the previous year. The mindshare of WatchGuard EPDR is 1.4%, down from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.7%
WatchGuard EPDR1.4%
Rapid7 InsightIDR1.3%
Other93.6%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Prajwal Chougale - PeerSpot reviewer
SPC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.
Petri Alhainen - PeerSpot reviewer
Administrator at Sulbana Oy
Balanced endpoint protection has improved forensic visibility and speeds threat investigation
I think there's always something that needs to be improved about WatchGuard EPDR, but I don't have something specific to say that you should do this or that. They are listening to the users, so they are fixing things as they've been found. I don't have any example to give. The pricing is always a thing where you need to be in the line that the balance to get it right is a challenging thing with WatchGuard EPDR. If you have good features, then you can have a little bigger price, but if you just get the balance right, that's important. I haven't used automated incident response in WatchGuard EPDR.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that you can select remote access of any machine for sandboxing."
"Cortex XDR by Palo Alto Networks has changed the way my security team detects, investigates, and responds to threats, as we are able to see the files, unwanted files, unsecured files, and unauthorized files, so we are quarantining them."
"Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
"The normal protection was really effective, and we detected situations that if we didn't have Cortex XDR by Palo Alto Networks, it's highly likely that we would have been affected, but it protected the infrastructure."
"The tool is designed to scale for large enterprises and handle large volumes of data."
"Its ability to react to cyber data attacks is awesome."
"The information the dashboard provides is very clear."
"Cortex XDR is stable, offering high quality and reliable performance."
"Rapid7's reporting is more robust than Tenable's."
"The solution provides satisfying native integration features"
"The web interface is great — very useful and user-friendly."
"This is a great product and the team is very willing to work with companies."
"The alerting to drive investigations and remediation has been its most valuable feature, plus the ability to quickly search multiple logs makes investigations easier."
"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
"The UI is very good."
"Technical support has always been top-notch when you can get through."
"The EDR has a high accuracy rate with only a few false positives."
"I think there's quite a good balance in everything with WatchGuard EPDR, with tools to do things and watch what's happening, and everything is in the same tools and quite well designed or thought about how to do things, which is the reason I've been enjoying them."
"It is stable, and the performance is good."
"What is really great about Panda Adaptive Defense 360 is its console in the cloud, and it can keep the inventory of software in the PC."
"The detection capabilities for malicious activities are effective."
"I can put tons of load on it."
"It offers an easy initial setup."
 

Cons

"They are charging for Network Traffic Analyzer (NTA) services, so if the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better."
"The downsides of Cortex XDR by Palo Alto Networks are that in many incidents, when I enter the causality chain, there are numerous logs."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
"We would also like to have advanced tech protection and email scanning."
"Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
"Additionally, I think the price is very high, and if it can be adjusted, I believe it will be a very good solution."
"Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
"When it comes to core analysis, and security analysis, Cortex needs to provide more information."
"I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part."
"Rapid7's customer support is awful. They didn't respond at all."
"The APIs can be further improved in Rapid7."
"Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one."
"There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on."
"One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
"It would be nice if Panda Security Adaptive Defense could come out with remote desktop usage."
"The gap between the two final conclusions is a problem, whether or not a file is known to be malware or is known to be safe."
"Panda Security Adaptive Defense can improve by including the intrusion and prevention system not only on their most expensive platform. Additionally, it blocks software that is legitimate from users. They complain and then we have to manually unblock the software, by hash, or we receive a message. Some of the prevention features are not available and this might cause us to need a separate firewall or something to protect the company."
"Their portal is, to me, in need of a lot of work. It's just not very good."
"It is hard to install and deploy on a Linux operating system."
"It needs some improvements in the DNS security feature. Currently, it does not have full DNS security. It only has semi-DNS security, which can be improved. It is an important feature for us, and it would be really good if they can improve the DNS security feature. Our group has some plans to change to Cisco AMP, which has features such as DNS, Umbrella. We are trying to learn about Cisco AMP and compare it with Panda."
"I think there was a little complexity in deployment when I actually deployed WatchGuard EPDR."
"They need to offer a clear dashboard so you can see everything everywhere all at once."
 

Pricing and Cost Advice

"Our customers have expressed that the price is high."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"It has reasonable pricing for the use cases it provides to the company."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"This is an expensive solution."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"It is "expensive" and flexible."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"It is more reasonably priced than other vendors."
"The pricing is good, and it is not very expensive."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"The pricing and licensing are competitive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"There is a license needed to use this solution and it is approximately $30 annually."
"The solution's pricing is better compared to other products."
"The licensing is subscription-based and priced well compared to other endpoint security solutions."
"The licensing costs are not too high. We pay about 20 Euros a year. It's a reasonable amount to pay."
"Panda is cloud-only and comes at a reasonable cost. It is a set price per seat."
"The price of this solution depends on the number of licenses that you are purchasing."
"I don't think Panda's license is too expensive, but they're charging more than it's worth. It's a yearly license. For 1,000 endpoints, it's around $18,000."
"The product is available at a high price."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
909,948 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
10%
Comms Service Provider
10%
Financial Services Firm
10%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
Comms Service Provider
11%
Computer Software Company
9%
Manufacturing Company
7%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise8
Large Enterprise2
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
What needs improvement with WatchGuard EPDR?
I think there's always something that needs to be improved about WatchGuard EPDR, but I don't have something specific...
What is your primary use case for WatchGuard EPDR?
I'm talking about WatchGuard EPDR, which is endpoint protection. I try to remember if we have them in our system, and...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
InsightIDR
Panda Adaptive Defense 360
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Liberty Wines, Pioneer Telephone, Visier
Indra, Valea AB, Fineit, Aemcom, Data Solutions INC., Gloucestershire NHS, Golden Star Resources Ltd, Hispania Racing Team, Instituto Dos Museus e da ConserÊo, Escuelas Pias Provincia Emaus, Axiom Housing Association, Municipality of Bjuv, Lesedi Nuclear, Mullsj_ municipality, Eng. skolan Norr AB, Dalakraft AB, Peter Green Haulage Ltd
Find out what your peers are saying about Rapid7 InsightIDR vs. WatchGuard EPDR and other solutions. Updated: August 2026.
909,948 professionals have used our research since 2012.