No more typing reviews! Try our Samantha, our new voice AI agent.

Symantec XDR vs Trellix XDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
120
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Symantec XDR
Ranking in Extended Detection and Response (XDR)
48th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Trellix XDR
Ranking in Extended Detection and Response (XDR)
20th
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.8%, down from 6.0% compared to the previous year. The mindshare of Symantec XDR is 0.6%, up from 0.2% compared to the previous year. The mindshare of Trellix XDR is 0.8%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.8%
Trellix XDR0.8%
Symantec XDR0.6%
Other93.8%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
BR
Cyber Security Consultant at I(TS)² Saudi Arabia
A scalable and stable solution with straightforward deployment
We can generate maps from the environment. For example, suppose there is a virus that has a zero-day attack and is publicly unknown. We can block that and keep it away from the network so it is not further replicated. It also has custom white and black lists. We can add a good reputation on both lists and use the sonar technology for Symantec and the online network for advanced reports.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Unified threat detection has improved investigations and now speeds up incident response
While Trellix XDR is a strong platform overall, there are a few areas where it could be improved. The initial setup and configuration can be complex, especially for organizations with diverse environments. Some additional advanced features also have a learning curve and may require extra training for security teams to fully utilize them. Moreover, reporting and dashboard customization could be more flexible, allowing users to create highly customized views and reports more easily. There are also areas that could optimize detection surveys. Addressing these areas would further enhance the overall experience and operational effectiveness. One additional improvement would be deeper integration with a wider range of third-party security tools and cloud platforms. While Trellix XDR integrates with many solutions, simplifying the integration management would help organizations with complex security ecosystems. I would like to see more out-of-the-box reports and executive-level dashboards that make it easier to communicate security metrics to leadership. Finally, continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness. Overall, these are areas that need refinement rather than being major concerns, as the platform still delivers strong security and operational value.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We can visualize and control the activities in the environment from anywhere."
"It blocks malicious files, prevents attacks, and doesn't require many updates because it is a very light application."
"Cortex XDR by Palo Alto Networks should be a stable solution."
"If any application performs suspicious activities, such as changing registries or modifying other applications, Cortex XDR detects and blocks the entire application."
"The most valuable for us is the correlation feature."
"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"The multi-layered approach to the product gives you confidence that it will stop exploits, ransomware, worms, or viruses from compromising endpoints, essentially providing peace of mind."
"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"We can block a virus that has a zero-day attack and is publicly unknown and keep it away from the network so it is not further replicated."
"You can advise the solution and protect your environment."
"Trellix XDR has positively impacted my organization in a couple of major ways: The efficiency of the SOC team has increased, and incident investigation speed has improved significantly."
"Since implementing Trellix XDR, I have noticed positive impacts on my organization."
"Trellix XDR has impacted my organization positively as it's a security solution that protects us from threats."
"Since implementing Trellix XDR, we have seen improvement in our threat detection and incident response capability."
"Trellix XDR has impacted my organization positively because time was definitely saved because of the automated response, and the positive impact was definitely there in terms of both time saved and people being cut down from the team to have a more efficient and cost-saving team."
"Trellix's technical support is helpful."
"Trellix XDR is an excellent solution that is continually improving."
"The AI-assisted troubleshooting and threat hunting capabilities, along with the machine learning functionality, are the biggest advantages of Trellix XDR that stand out for me."
 

Cons

"Cortex XDR by Palo Alto Networks is a strong tool, but it is true that digesting information sometimes makes the tool go a little bit slower."
"The solution lacks real-time, on-demand antivirus."
"The MAC agent is not as robust feature-wise as the PC version."
"The deployment is pretty hard."
"The onboarding process could be better."
"In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."
"Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere."
"A better pricing plan would make this product more competitive."
"The solution should have better reporting."
"The main area regarding Trellix XDR improvement is that setup and tuning can be complex because it requires a skilled analyst based on utilization."
"Another reason is that their support sometimes is poor. For example, I had experience when my ticket was opened for a few months, and I pinged them every week, and they haven't responded to me."
"Customer support is average, depending on who the call gets to, escalation, and how quickly they respond."
"Price is the main area for improvement in the product."
"The platform should enhance compatibility with all other SIEM solutions."
"We have left Trellix XDR. The pricing was the main factor because the features were not there and they were charging more from us."
"I believe Trellix XDR could improve better visualization of attack paths and threat relationships."
"The EdgeGear solution is an area that requires attention, specifically regarding AI solutions and intelligence features."
 

Pricing and Cost Advice

"The tool's price is moderate."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"I feel it is fairly priced."
"The price of the solution is high for the license and in general."
"Cortex XDR's pricing is ok."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"When we first bought it, it was a bit expensive, but it was worth it. The licensing was straightforward."
"The cost depends on your chosen license type, like Pro or other licenses."
Information not available
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
915,817 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
No data available
Outsourcing Company
16%
Financial Services Firm
15%
Computer Software Company
12%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise21
Large Enterprise56
No data available
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise8
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Trellix XDR?
My experience with pricing, setup cost, and licensing shows that the pricing is very competitive and not overly expen...
What needs improvement with Trellix XDR?
Price is the main area for improvement in the product. Overall, it seems to be positioned more for larger organizatio...
What is your primary use case for Trellix XDR?
I have used Trellix XDR for two years in a partnership capacity.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
MVision XDR, MVision eXtended Detection and Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about SentinelOne, TrendAI, Palo Alto Networks and others in Extended Detection and Response (XDR). Updated: September 2026.
915,817 professionals have used our research since 2012.