No more typing reviews! Try our Samantha, our new voice AI agent.

Sangfor Endpoint Secure vs WatchGuard EPDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Sangfor Endpoint Secure
Ranking in Endpoint Detection and Response (EDR)
30th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
11
Ranking in other categories
No ranking in other categories
WatchGuard EPDR
Ranking in Endpoint Detection and Response (EDR)
19th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Protection Platform (EPP) (16th)
 

Mindshare comparison

As of September 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.6%, down from 3.9% compared to the previous year. The mindshare of Sangfor Endpoint Secure is 0.8%, up from 0.7% compared to the previous year. The mindshare of WatchGuard EPDR is 1.4%, down from 1.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.6%
WatchGuard EPDR1.4%
Sangfor Endpoint Secure0.8%
Other94.2%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
OA
Coordinator Associate at National Institute of Cardiovascular Diseases
Quick threat response and behavior analysis while enhancing network security
The main use case is usually related to security. It deals with attacks that come day-to-day such as zero-day attacks and APT attacks. Our main task is to secure the network infrastructure in the hospital where I work It facilitates the departments of IT and other departments to procure and…
Petri Alhainen - PeerSpot reviewer
Administrator at Sulbana Oy
Balanced endpoint protection has improved forensic visibility and speeds threat investigation
I think there's always something that needs to be improved about WatchGuard EPDR, but I don't have something specific to say that you should do this or that. They are listening to the users, so they are fixing things as they've been found. I don't have any example to give. The pricing is always a thing where you need to be in the line that the balance to get it right is a challenging thing with WatchGuard EPDR. If you have good features, then you can have a little bigger price, but if you just get the balance right, that's important. I haven't used automated incident response in WatchGuard EPDR.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The good thing about the product is that it's always scanning."
"The solution is a new generation XDR that has a lot of artificial intelligence modules."
"Automation and playbooks have helped me significantly, as Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, efficiently detecting and blocking malicious attacks with firewalls while eliminating workload and speeding responses for next-generation operations."
"Based on my experience, I would recommend Cortex XDR by Palo Alto Networks to other people."
"Palo Alto is the core of the security infrastructure in the environment."
"I recommend this solution to others because it is easy to manage, reliable, and overall good to use."
"I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities."
"If you are looking to deploy a security solution as a whole, this is a good option."
"I like the tool's honeypot feature. Some features include having a honeypot to detect attacks in a certain area. Additionally, there is RDP protection, which means that when we remote into our server or any endpoint, we must enter a password as a second layer of security. It can also integrate with next-generation firewalls."
"The tool's most valuable features are control access, endpoint security, and load balancing of ISPs."
"The user-friendliness of Sangfor Endpoint Secure is particularly impressive. Even with basic technical knowledge, users can easily navigate the system, make changes, and implement updates."
"What stands out to me is the dual-end user interface they provide."
"The most valuable feature I have found in the system is its comprehensive end-to-end protection."
"The real-time monitoring feature of Sangfor Endpoint Secure is truly real-time, with no delay compared to other solutions."
"We use the product for network protection from any malicious threat."
"The tool's AI feature is helpful in endpoint security."
"It offers an easy initial setup."
"It is remarkably easy to deploy."
"The dashboard management feature is valuable."
"We have had a good experience with customer service and support."
"We have control over our devices, specifically USB ports, allowing us to block or control the traffic."
"The core functionality of the product is very impressive and I recommend that people use it."
"The solution protects our equipment and it works quietly in the background, so as not to disrupt employees."
"I can put tons of load on it."
 

Cons

"In general, the price could be more competitive."
"If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."
"It would be good if they could make an exception for applications. Sometimes, it can be a bit of a challenge to make exceptions for certain applications that have been used as rogue."
"There are some false positives."
"When it comes to core analysis, and security analysis, Cortex needs to provide more information."
"Fine-tuning the detection policy requires experience because the policy is very complex in Cortex XDR by Palo Alto Networks, and we get high false positive alerts."
"The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
"The onboarding process could be better."
"It is complicated to establish a tunnel due to technical issues in the VPN system."
"Sometimes, the VPN is not secure and doesn't work properly in Sangfor Endpoint Secure."
"The interface has too many buttons, making it cluttered."
"When an issue occurs, the response time for first-level support and the time taken for meetings could be improved."
"I face issues while migrating from Kaspersky to Sangfor Endpoint Secure."
"It would be much more convenient if the migration tool could be installed directly on the customer's VMs, enabling a smoother migration process to the new infrastructure, with potential restrictions addressed accordingly."
"Sangfor Endpoint Secure should include healing capabilities."
"Currently, the tool lacks reporting functionalities."
"Panda Security Adaptive Defense can improve by including the intrusion and prevention system not only on their most expensive platform. Additionally, it blocks software that is legitimate from users. They complain and then we have to manually unblock the software, by hash, or we receive a message. Some of the prevention features are not available and this might cause us to need a separate firewall or something to protect the company."
"Only the DNS filtering part could be improved, and nothing else apart from this needs correction."
"It needs some improvements in the DNS security feature. Currently, it does not have full DNS security."
"Either conclusion means we will have either false positives or false negatives."
"The Linux installation is performed on the command line and they need a package installer for that operating system."
"This solution can't scale how we like."
"An area for improvement would be the software deployment to seamlessly deploy software packages across multiple machines simultaneously, and to enhance the remote monitoring capabilities."
"Although the antivirus solution is so good that we've never suffered from an attack, we've had a few problems with false positives where they weren't correct."
 

Pricing and Cost Advice

"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"I don't like that they have different types of licenses."
"Cortex XDR’s pricing is very reasonable."
"I am using the Community edition."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"I don't recall what the cost was, but it wasn't really that expensive."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"The product is expensive compared to other vendors."
"Price-wise, Sangfor Endpoint Secure can be considered a competitively priced product in the market as it offers quite low prices compared to other solutions."
"The solution is cheap. It is cheaper than other products by 15-20 percent."
"Its "pay as you grow" model offers cost-effectiveness compared to major cloud providers."
"Sangfor Endpoint Secure's pricing is cheap. I rate it seven out of ten."
"Sangfor Endpoint Secure is not a cheap solution."
"We were using Hyper-V. So, we switched to Sangfor because of the pricing."
"I don't think Panda's license is too expensive, but they're charging more than it's worth. It's a yearly license. For 1,000 endpoints, it's around $18,000."
"The solution is priced well for what features it provides."
"The product is available at a high price."
"The solution's pricing is better compared to other products."
"The licensing costs are not too high. We pay about 20 Euros a year. It's a reasonable amount to pay."
"There is a license needed to use this solution and it is approximately $30 annually."
"The licensing is subscription-based and priced well compared to other endpoint security solutions."
"Customers need to pay monthly licensing costs for Panda Security Adaptive Defense, which is not expensive."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
17%
Comms Service Provider
11%
Media Company
7%
Outsourcing Company
6%
Comms Service Provider
11%
Outsourcing Company
9%
Computer Software Company
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise3
By reviewers
Company SizeCount
Small Business28
Midsize Enterprise8
Large Enterprise2
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Sangfor Endpoint Secure?
The interface has too many buttons, making it cluttered. It would be better if it were a simplified version with fewe...
What is your primary use case for Sangfor Endpoint Secure?
Sangfor Endpoint Secure is easy to handle with its user-friendly interface. The four engines it utilizes for endpoint...
What advice do you have for others considering Sangfor Endpoint Secure?
At first, people might not understand the interface, which is why it should be simplified. However, once they underst...
What needs improvement with WatchGuard EPDR?
I think there's always something that needs to be improved about WatchGuard EPDR, but I don't have something specific...
What is your primary use case for WatchGuard EPDR?
I'm talking about WatchGuard EPDR, which is endpoint protection. I try to remember if we have them in our system, and...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Panda Adaptive Defense 360
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Indra, Valea AB, Fineit, Aemcom, Data Solutions INC., Gloucestershire NHS, Golden Star Resources Ltd, Hispania Racing Team, Instituto Dos Museus e da ConserÊo, Escuelas Pias Provincia Emaus, Axiom Housing Association, Municipality of Bjuv, Lesedi Nuclear, Mullsj_ municipality, Eng. skolan Norr AB, Dalakraft AB, Peter Green Haulage Ltd
Find out what your peers are saying about Sangfor Endpoint Secure vs. WatchGuard EPDR and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.