No more typing reviews! Try our Samantha, our new voice AI agent.

Symantec XDR vs Trellix XDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
5th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Symantec XDR
Ranking in Extended Detection and Response (XDR)
47th
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Trellix XDR
Ranking in Extended Detection and Response (XDR)
35th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.7%, down from 5.1% compared to the previous year. The mindshare of Symantec XDR is 0.5%, up from 0.1% compared to the previous year. The mindshare of Trellix XDR is 0.8%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.7%
Trellix XDR0.8%
Symantec XDR0.5%
Other94.0%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
BR
Cyber Security Consultant at I(TS)² Saudi Arabia
A scalable and stable solution with straightforward deployment
We can generate maps from the environment. For example, suppose there is a virus that has a zero-day attack and is publicly unknown. We can block that and keep it away from the network so it is not further replicated. It also has custom white and black lists. We can add a good reputation on both lists and use the sonar technology for Symantec and the online network for advanced reports.
Ahmed El-Sakka - PeerSpot reviewer
Solutions Architect at Mideast Communication Systems-MCS
AI-driven threat hunting has boosted incident response and simplifies unified security management
The AI-assisted troubleshooting and threat hunting capabilities, along with the machine learning functionality, are the biggest advantages of Trellix XDR that stand out for me. The automated threat detection part is used for security, and it is part of the offering. The core functionality includes EDR and NDR, and Trellix XDR gets threat detection on both the network and endpoint levels. Trellix XDR adds the excellent threat hunting capabilities as well, and it includes forensics. Regarding contextual data enrichment, it helps me prioritize threats with Trellix XDR. The data enrichment is intent-based, where I can describe what I want to see, and it will retrieve that information for me. It provides logs and feedback in very understandable English commands when it comes to context. This is accomplished through their use of AI.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We think that this product will help us grow, as it meets our needs currently and we can grow with it over time."
"Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
"Based on my experience, I would recommend Cortex XDR by Palo Alto Networks to other people."
"Palo Alto is the best security solution in the market."
"Cortex XDR can integrate the firewalls and determine the tendencies of the attacks. It's a new generation antivirus, with protection endpoints and detection response. It is very easy to use and everybody can operate the solution."
"The positive impacts I see from Cortex XDR by Palo Alto Networks include a complete 360-degree view of our security posture altogether, being a uniform platform where we are ingesting logs from multiple resources."
"Threat identification and detection are the most valuable features of this solution."
"There has been a significant reduction of approximately 70% to 80% in our internal MTTR and MTTD metrics, now around five to eight minutes whereas previously it was hours, which has helped tremendously."
"We can block a virus that has a zero-day attack and is publicly unknown and keep it away from the network so it is not further replicated."
"You can advise the solution and protect your environment."
"Because Trellix gives us multiple types of modules, we are using a single ePO console for multiple solutions including application control, DLP, and XDR."
"The AI-assisted troubleshooting and threat hunting capabilities, along with the machine learning functionality, are the biggest advantages of Trellix XDR that stand out for me."
"The analytics assessment and flexibility of the platform are valuable."
"It contributes to our system's robust event detection and analysis, enabling us to respond effectively to incidents."
"Trellix XDR is an excellent solution that is continually improving."
 

Cons

"The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
"There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
"Previously, the endpoint would leave the environment, not being on our VPN, essentially unable to interact with the server to upload files."
"The main issue I could point out is the offline agents and the way that it is missing."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"The connection to the internet has not performed as expected."
"The dashboard could use some significant improvement, just making it more useful with more information. It has a limited amount of information right now. It is customizable, but I'd love to see a better out-of-box dashboard."
"The solution should have better reporting."
"The solution should have better reporting."
"The CPU utilization is very high with Trellix XDR; we are getting multiple types of CPU utilization from the EPP solution, with the EPP agent reaching as high as 80 percent CPU utilization, which creates big challenges for us."
"The EdgeGear solution is an area that requires attention, specifically regarding AI solutions and intelligence features."
"Trellix XDR should get involved in AI security itself."
"The platform should enhance compatibility with all other SIEM solutions."
"Technical support is crucial, especially when facing critical issues. It's rated six out of ten. Improvements are needed in the support sector, with a focus on providing expert assistance during production periods."
 

Pricing and Cost Advice

"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The pricing is a little bit on the expensive side."
"This is an expensive solution."
"The pricing is okay, although direct support can be expensive."
"Cortex XDR’s pricing is very reasonable."
"It has reasonable pricing for the use cases it provides to the company."
Information not available
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
892,776 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
12%
Comms Service Provider
8%
Manufacturing Company
8%
No data available
Computer Software Company
18%
Comms Service Provider
10%
Financial Services Firm
10%
Healthcare Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise20
Large Enterprise48
No data available
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Trellix XDR?
Since I'm a technical engineer, I don't deal with pricing or licensing. Our sales team handles those aspects.
What needs improvement with Trellix XDR?
The CPU utilization is very high with Trellix XDR. We are getting multiple types of CPU utilization from the EPP solu...
What is your primary use case for Trellix XDR?
We are selling Trellix XDR products including DLP and EPP solutions. We sell Trellix XDR for endpoint protection. We ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
MVision XDR, MVision eXtended Detection and Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about CrowdStrike, SentinelOne, TrendAI and others in Extended Detection and Response (XDR). Updated: April 2026.
892,776 professionals have used our research since 2012.