No more typing reviews! Try our Samantha, our new voice AI agent.

SonicWall Capture Client vs Trellix Endpoint Detection and Response (EDR) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
4.6
Cortex XDR offers high ROI with reduced costs, improved efficiency, affordable pricing, and enhanced security features compared to competitors.
Sentiment score
1.0
SonicWall Capture Client offers cost savings, improved security, reduced manual work, lower infection rates, and easy deployment for better productivity.
Sentiment score
6.3
Organizations praise Trellix EDR for increased efficiency, improved compliance, and operational resilience, despite diverse financial outcomes.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cyber Security Manager at Welab bank
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
Detection and Response Consultant at Inovasys
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Network Security Engineer at Cyberwell Solution
The advanced detection and mitigation capabilities ensure the highest level of protection and proper detection for command and control and bot attacks.
Business Development Manager at a retailer with 10,001+ employees
Nowadays, the security team can identify, analyze and contain threats from a single console, considerably reducing the time needed to take corrective actions.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
 

Customer Service

Sentiment score
7.0
Cortex XDR is praised for technical support and responsiveness, despite occasional delays and varying regional support quality.
Sentiment score
6.0
SonicWall Capture Client service is accessible and multilingual, but resolution speed and process length receive mixed reviews.
Sentiment score
6.8
Trellix EDR has mixed reviews, with critiques on support response and praise for professionalism and communication skills.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
Head of data centers at a non-profit with 10,001+ employees
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
Senior Process Expert at A.P. Moller - Maersk
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
Chief of IT Architecture at a financial services firm with 10,001+ employees
Partners can purchase single endpoints at prices equivalent to 1,000-endpoint deals, providing an advantage for managed security service provider partners.
Product Manager at wahana piranti teknologi
SonicWall is different. All the time they will make reports. Your trouble ticket is in this status, the trouble ticket needs this information.
CISO at PCRA
While their escalation process is understandable, it can be time-consuming as all logs need to be provided multiple times across different service levels.
Product Manager at a tech services company with 11-50 employees
The support team has demonstrated solid knowledge, providing adequate follow-up to cases and maintaining effective communication.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
I have contracted support and also have an operating control so I can get various types of support.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
On our servers, we do not want it to touch our resources, so we deployed Sophos XDR on the server.
Security Administrator at a insurance company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
7.5
Cortex XDR scales well for different organizations, but may be costly for small enterprises despite its cloud-based efficiency.
Sentiment score
7.0
SonicWall Capture Client is ideal for SMEs due to its adaptability, scalability, simple interface, and flexible licensing.
Sentiment score
7.2
Trellix EDR offers scalable deployment across diverse business sizes, with efficient management and adaptability for extensive network use.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Assistant Security Architect at Cloudnomics
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Junior Security Analyst at ITSEC Asia
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
Head of data centers at a non-profit with 10,001+ employees
There are no restrictions on the scalability of SonicWall Capture Client.
Product Manager at a tech services company with 11-50 employees
SonicWall Capture Client is accessed via cloud-based management console.
Product Manager at a tech services company with 11-50 employees
The installation process is straightforward, requiring only five pilot installations to enable customers to complete the remaining installations independently.
Product Manager at wahana piranti teknologi
Trellix Endpoint Detection and Response (EDR) is built on top of the ePO (ePolicy Orchestrator) management architecture, which is globally recognized as the most scalable endpoint management platform in cybersecurity history.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
The platform has made it possible to efficiently expand endpoint coverage without increasing operational complexity.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
 

Stability Issues

Sentiment score
8.0
Cortex XDR by Palo Alto Networks is highly stable, resolving early issues and delivering consistent, reliable performance with minimal downtime.
Sentiment score
8.6
SonicWall Capture Client is praised for stability and reliability, despite some performance impacts from high resource consumption.
Sentiment score
8.0
Trellix EDR is generally stable and reliable, with improved efficiency but potential deployment challenges from architecture changes.
Cortex remains fast and responsive, even with increasing data and alerts.
Final Year Student at Gitam University
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Senior Process Expert at A.P. Moller - Maersk
Cortex XDR by Palo Alto Networks can be trusted completely.
Soc Analyst at Softcell Technologies Limited
They have different data centers in the entire world, and when some data center, for example, here in Texas or in California, experiences some issue, they very quickly switch to another data center and they send a notification from the degradation.
CISO at PCRA
So I have to use Sophos XDR on servers because Sophos XDR does not consume resources.
Security Administrator at a insurance company with 1,001-5,000 employees
 

Room For Improvement

Cortex XDR needs better integration, user interface, automation, and competitive pricing, along with reduced performance issues and clearer features.
SonicWall Capture Client needs performance, interface, compatibility, and report upgrades, plus mobile access and improved server proximity in South America.
Trellix EDR requires improved automation, integration, resource optimization, alerting, and API functionality to address performance and support challenges.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
Final Year Student at Gitam University
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Pre Sales Architect at network techlab
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Cyber Security Information Security Specialist at MHM Holding GmbH
I believe SonicWall needs to make more testing regarding the compatibilities with some commercial applications.
CISO at PCRA
One of the drawbacks is that I cannot use Advanced and Premier licenses within a single tenant, which can be problematic when users need to deploy different licenses.
Product Manager at a tech services company with 11-50 employees
XDR cannot be used unless MDR services are purchased with SonicWall.
Product Manager at a tech services company with 11-50 employees
I am seeing, for workflows, some sort of ethical hacking to test our environment.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
Trellix Endpoint Detection and Response (EDR) scores highly because of its sheer depth of endpoint visibility, the precision of its behavior-based detection, and the massive time savings we get from its AI-guided investigations.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
Trellix Endpoint Detection and Response (EDR) is interesting and is a very good entry point that has been evolving through the last years.
Committee Of IT Cybersececurity at a energy/utilities company with 51-200 employees
 

Setup Cost

Cortex XDR's pricing is seen as reasonable for its advanced capabilities, though setup costs can be perceived as high.
SonicWall Capture Client offers competitive pricing, but costs may vary and can be high for small businesses and certain infrastructures.
Trellix EDR offers tier-based pricing suitable for midsized businesses with competitive discounts and cost-effective deployment.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
Consultant at a tech services company with 1,001-5,000 employees
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Senior Process Expert at A.P. Moller - Maersk
Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Soc Analyst at Softcell Technologies Limited
Trend Micro is more expensive, around 15% or 20% more expensive than SonicWall Capture Client.
CISO at PCRA
SonicWall Capture Client offers a cost-effective solution that's cheaper compared to other vendors like CrowdStrike.
Product Manager at a tech services company with 11-50 employees
Trellix is highly competitive in the enterprise market because they offer aggressive volume-tiered discounting levels, such as levels A through D.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
The solution offers a robust set of detection, investigation and response capabilities that provide value for the investment made.
Especialista Seguridad Endpoint at a tech services company with 51-200 employees
My experience with pricing, setup cost, and licensing is very cost-effective.
Business Development Manager at a retailer with 10,001+ employees
 

Valuable Features

Cortex XDR enhances security with AI-driven analytics, user-friendly management, cloud deployment, and comprehensive threat response features.
SonicWall Capture Client provides robust security with rollback, machine learning, user-friendly interface, and integration with SentinelOne.
Trellix EDR delivers advanced threat detection, AI analytics, centralized management, and low false positives for scalable cybersecurity.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
Cyber Security Manager at Welab bank
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
Pre Sales Architect at network techlab
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
Final Year Student at Gitam University
Machine learning is particularly effective due to SonicWall sandboxing's threat intelligence database of approximately 7.1 billion entries.
Product Manager at wahana piranti teknologi
One is that users can use the sandbox of SonicWall, which is called Capture ATP for free.
Product Manager at a tech services company with 11-50 employees
The troubleshooting and the support service from SonicWall for this suite in particular is very easy and very quick.
CISO at PCRA
Trellix Endpoint Detection and Response (EDR) has very good threat hunting capability.
Security Administrator at a insurance company with 1,001-5,000 employees
Advanced detection capabilities ensure that targeted attacks will be detected and blocked before they arrive at our network.
Business Development Manager at a retailer with 10,001+ employees
Trellix Endpoint Detection and Response (EDR) has positively impacted my organization by allowing us to protect our servers from malware and attacks, ensuring we can safeguard our clients.
Senior Information Security Specialist at a consultancy with 51-200 employees
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
SonicWall Capture Client
Ranking in Endpoint Detection and Response (EDR)
33rd
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
12
Ranking in other categories
Endpoint Protection Platform (EPP) (34th)
Trellix Endpoint Detection ...
Ranking in Endpoint Detection and Response (EDR)
14th
Average Rating
7.6
Reviews Sentiment
7.0
Number of Reviews
29
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.7%, down from 3.8% compared to the previous year. The mindshare of SonicWall Capture Client is 0.8%, up from 0.6% compared to the previous year. The mindshare of Trellix Endpoint Detection and Response (EDR) is 0.9%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.7%
Trellix Endpoint Detection and Response (EDR)0.9%
SonicWall Capture Client0.8%
Other94.6%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
HT
Product Manager at wahana piranti teknologi
Has consistently delivered double-layer protection and simplified policy application while needing mobile compatibility and better MacOS support
A significant limitation is that SonicWall Capture Client cannot be installed on smartphones, as there is no mobile version available.Occasionally, the Sentinel engine becomes unresponsive, particularly when customers do not properly restart or shutdown their systems. This requires a hard restart after installation to resolve the issue. Installation on Mac OS can be challenging, requiring multiple attempts due to version compatibility requirements. We must ensure the SonicWall Capture Client version is stable for Mac OS. The RAM usage is higher compared to SentinelOne, utilizing approximately 150 megabytes of memory. This is a common concern from customers, and reducing RAM consumption would be beneficial.
Duncan  Kims - PeerSpot reviewer
Business Development Manager at a retailer with 10,001+ employees
Advanced detection has reduced targeted attacks and builds daily confidence in our defenses
Trellix Endpoint Detection and Response (EDR) has a very low false positive rate compared to other products, thus increasing the SOC efficiency in how my team relies on the solution day-to-day.With the best features Trellix Endpoint Detection and Response (EDR) offers, ease of SOAR integration helps to automate the IOC distribution, and our security team and management trust the product. Advanced detection capabilities ensure that targeted attacks will be detected and blocked before they arrive at our network. SOAR integration has assisted our security team and management in trusting the product.
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
10%
Comms Service Provider
10%
Financial Services Firm
10%
Comms Service Provider
11%
Construction Company
9%
Government
8%
Outsourcing Company
8%
Financial Services Firm
14%
Construction Company
8%
Manufacturing Company
7%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business12
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise3
Large Enterprise13
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for SonicWall Capture Client?
I am familiar with the pricing of SonicWall Capture Client, and we have two parameters for pricing. One is the MSP ve...
What needs improvement with SonicWall Capture Client?
While I believe SonicWall Capture Client is a good tool, it has some incompatibility with some applications that is v...
What is your primary use case for SonicWall Capture Client?
We have a partnership with SonicWall, and we are not just a customer, but a user. We have been partners since 2012 an...
What is your experience regarding pricing and costs for McAfee MVISION Endpoint Detection and Response?
My experience with pricing, implementation costs and platform licensing has been positive. The solution offers a robu...
What needs improvement with McAfee MVISION Endpoint Detection and Response?
Although Trellix Endpoint Detection and Response (EDR) offers those detection, investigation and response capabilitie...
What is your primary use case for McAfee MVISION Endpoint Detection and Response?
The main use case for Trellix Endpoint Detection and Response (EDR) in my organization is for continuous monitoring o...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
McAfee MVISION EDR, MVISION EDR, MVISION Endpoint Detection and Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Luton College
Sutherland Global Services
Find out what your peers are saying about SonicWall Capture Client vs. Trellix Endpoint Detection and Response (EDR) and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.