No more typing reviews! Try our Samantha, our new voice AI agent.

Symantec XDR vs Trellix XDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Symantec XDR
Ranking in Extended Detection and Response (XDR)
51st
Average Rating
8.0
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Trellix XDR
Ranking in Extended Detection and Response (XDR)
18th
Average Rating
7.6
Reviews Sentiment
6.6
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of Symantec XDR is 0.5%, up from 0.1% compared to the previous year. The mindshare of Trellix XDR is 0.8%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.5%
Trellix XDR0.8%
Symantec XDR0.5%
Other94.2%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
BR
Cyber Security Consultant at I(TS)² Saudi Arabia
A scalable and stable solution with straightforward deployment
We can generate maps from the environment. For example, suppose there is a virus that has a zero-day attack and is publicly unknown. We can block that and keep it away from the network so it is not further replicated. It also has custom white and black lists. We can add a good reputation on both lists and use the sonar technology for Symantec and the online network for advanced reports.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Unified threat detection has improved investigations and now speeds up incident response
While Trellix XDR is a strong platform overall, there are a few areas where it could be improved. The initial setup and configuration can be complex, especially for organizations with diverse environments. Some additional advanced features also have a learning curve and may require extra training for security teams to fully utilize them. Moreover, reporting and dashboard customization could be more flexible, allowing users to create highly customized views and reports more easily. There are also areas that could optimize detection surveys. Addressing these areas would further enhance the overall experience and operational effectiveness. One additional improvement would be deeper integration with a wider range of third-party security tools and cloud platforms. While Trellix XDR integrates with many solutions, simplifying the integration management would help organizations with complex security ecosystems. I would like to see more out-of-the-box reports and executive-level dashboards that make it easier to communicate security metrics to leadership. Finally, continuous enhancement to automation and AI-driven threat prioritization would further reduce analysts' workflow and improve response effectiveness. Overall, these are areas that need refinement rather than being major concerns, as the platform still delivers strong security and operational value.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"There has been a significant reduction of approximately 70% to 80% in our internal MTTR and MTTD metrics, now around five to eight minutes whereas previously it was hours, which has helped tremendously."
"The tool's use cases are relevant to security."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"Technical support is the best in class, in my opinion, because they have invested heavily in research and development."
"One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
"The good thing about the product is that it's always scanning."
"My advice for others looking into using Cortex is that it is very easy to use and very useful for the customer environment, whether it's a public or private one."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"You can advise the solution and protect your environment."
"We can block a virus that has a zero-day attack and is publicly unknown and keep it away from the network so it is not further replicated."
"Trellix XDR has impacted my organization positively because time was definitely saved because of the automated response, and the positive impact was definitely there in terms of both time saved and people being cut down from the team to have a more efficient and cost-saving team."
"Trellix XDR is an excellent solution that is continually improving."
"The AI-assisted troubleshooting and threat hunting capabilities, along with the machine learning functionality, are the biggest advantages of Trellix XDR that stand out for me."
"Since implementing Trellix XDR, we have seen improvement in our threat detection and incident response capability."
"The analytics assessment and flexibility of the platform are valuable."
"Since implementing Trellix XDR, I have noticed positive impacts on my organization."
"Trellix's technical support is helpful."
"The best features of Trellix XDR are the in-depth analysis it provides."
 

Cons

"Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere."
"Fine-tuning the detection policy requires experience because the policy is very complex in Cortex XDR by Palo Alto Networks, and we get high false positive alerts."
"Based on our experience so far, its implementation is quite complex."
"The GUI could be improved."
"The installation should be easier and the Palo Alto pre-sales and sales teams should have more information on the product because they don't know what they are selling."
"To jump from the partner to Palo Alto directly was challenging."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"There's room for improvement with Mac device installations, which can be challenging."
"The solution should have better reporting."
"The EdgeGear solution is an area that requires attention, specifically regarding AI solutions and intelligence features."
"I believe Trellix XDR could improve better visualization of attack paths and threat relationships."
"The main area regarding Trellix XDR improvement is that setup and tuning can be complex because it requires a skilled analyst based on utilization."
"Trellix XDR should get involved in AI security itself."
"Price is the main area for improvement in the product."
"Another reason is that their support sometimes is poor. For example, I had experience when my ticket was opened for a few months, and I pinged them every week, and they haven't responded to me."
"The initial setup and configuration can be complex, especially for organizations with diverse environments."
"The platform should enhance compatibility with all other SIEM solutions."
 

Pricing and Cost Advice

"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The cost depends on your chosen license type, like Pro or other licenses."
"Cortex XDR’s pricing is very reasonable."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
Information not available
Information not available
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
909,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
No data available
Financial Services Firm
15%
Computer Software Company
13%
Outsourcing Company
11%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
No data available
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise3
Large Enterprise8
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Trellix XDR?
My experience with pricing, setup cost, and licensing shows that the pricing is very competitive and not overly expen...
What needs improvement with Trellix XDR?
I believe Trellix XDR can be improved with more automation. I would like more improvements in terms of response.
What is your primary use case for Trellix XDR?
My main use case for Trellix XDR is supporting our clients and their EDR requirements. A specific example of how I us...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
MVision XDR, MVision eXtended Detection and Response
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Information Not Available
Find out what your peers are saying about SentinelOne, CrowdStrike, TrendAI and others in Extended Detection and Response (XDR). Updated: July 2026.
909,099 professionals have used our research since 2012.