No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2800860 - PeerSpot reviewer
MDR Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Mar 16, 2026
Advanced analytics have detected credential threats and capture many mitre-based anomalies
Pros and Cons
  • "Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard."
  • "The downsides of Cortex XDR by Palo Alto Networks are that in many incidents, when I enter the causality chain, there are numerous logs."

What is our primary use case?

My use cases for Cortex XDR by Palo Alto Networks are mostly for the Palo Alto products. Cortex XDR's use cases are many, including local malware analysis, WildFire analysis, and rare connections to external domains. Additionally, XDR analytics provide detection for abnormal RPC communication, DLL hijacking, credential read, credential harvesting, and in-process shell communication. Many of those use cases will be present in my environment.

How has it helped my organization?

What I like most about Cortex XDR by Palo Alto Networks is that it captures credential-related incidents and many MITRE Framework-related incidents. Many MITRE Framework techniques and tactics are captured as anomalies, which is one of the major advantages.

What is most valuable?

Cortex XDR's agent has the ability to block sophisticated threats in real time, as it has the facility to block many real-time attacks. However, the policy needs to be well-structured, because some organizations may indicate that certain executions can be allowed, which should not be permitted. Mostly, a restricted environment should be enforced, but the agent does have the facility to block approximately ninety percent of threats. I'm not claiming one hundred percent, but this capability is definitely present.

What needs improvement?

The downsides of Cortex XDR by Palo Alto Networks are that in many incidents, when I enter the causality chain, there are numerous logs. From that abundance of logs, I need to search for a particular event, but it is not properly matched in the initial view itself, and I have to dig through the logs to find the relevant information. For many multiple incidents, I have to create and search for a query and search the logs within that particular timeframe. The logs do not capture properly within the incident itself, which is one disadvantage.

AI-driven endpoint security helps in reducing risks. While this feature has not been implemented yet for Cortex XDR by Palo Alto Networks, it will be implemented in the future.

Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with Cortex XDR by Palo Alto Networks for three years.

What do I think about the stability of the solution?

I have seen some lagging, crashing, or downtime, but I don't think it's due to Cortex XDR by Palo Alto Networks itself. It's because of the logs injected into the system. When proper licensing is in place for the volume of logs, everything is fine, but if there are more logs than licensed, then performance issues will occur.

What do I think about the scalability of the solution?

I would rate the scalability of Cortex XDR by Palo Alto Networks as a seven out of ten.

How are customer service and support?

I have contacted the technical support and customer support. The speed and quality of support for Cortex XDR by Palo Alto Networks are quite good. Speed and responsiveness are satisfactory overall. If I were to rate them on a scale from one to ten, I would give them an eight.

Which solution did I use previously and why did I switch?

I have used solutions similar to Cortex XDR by Palo Alto Networks, including Defender and CrowdStrike. When I compare them, Cortex XDR by Palo Alto Networks has more visibility into incident names and more detailed explanations. When it comes to CrowdStrike, it's almost the same, with not much divergence between them. For all three solutions, the complexity in log search is common across the board.

How was the initial setup?

I hear that the deployment of Cortex XDR by Palo Alto Networks is easy, but I'm not involved in the deployment process. I am an end-user for that solution, not an administrator. The person who communicated with me asked about my role, and I indicated that I'm not a power user; I'm an end-user that uses logs, alerts, and incidents for analysis. From what I have heard, deployment is very straightforward and not that difficult. It's simply an installation of one agent.

What other advice do I have?

Cortex XDR by Palo Alto Networks saves time in various ways, although the user interface is fairly standard. It's similar to any other XDR or EDR tool, with nothing particularly special about it; it's almost all the same as competitors.

The user interface of Cortex XDR by Palo Alto Networks is quite good. I have access to the dashboard facility and everything, so it's effective overall.

If a person has EDR knowledge from working with CrowdStrike or Defender, they can easily learn Cortex XDR by Palo Alto Networks. However, a person coming from a SIEM background will take some additional time. I would rate this product an eight overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Mar 16, 2026
Flag as inappropriate
PeerSpot user
Olive Kusumbara - PeerSpot reviewer
Consultant at a tech services company with 1,001-5,000 employees
MSP
Top 5
Nov 4, 2025
Has enabled secure threat detection with minimal disruption and simplified deployment
Pros and Cons
  • "Cortex XDR by Palo Alto Networks's ability to block sophisticated threats in real time is quite good and is on par with SentinelOne's."
  • "If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."

What is most valuable?

I recommend Cortex XDR by Palo Alto Networks for a company that would like to have a more stable platform that does not disrupt their business or applications.

Cortex XDR by Palo Alto Networks's ability to block sophisticated threats in real time is quite good and is on par with SentinelOne's.

I assess the effectiveness of Cortex XDR by Palo Alto Networks's AI-driven endpoint security and find that both have very good results. The difference is around the details. SentinelOne is winning in this area in terms of the detailed information that can be captured and the detailed information in terms of the detections. SentinelOne also has superior storyline capabilities, which is why I think we use it for forensics as well. Cortex XDR by Palo Alto Networks is winning due to the simplicity and non-intrusive detection capabilities.

In terms of detections, SentinelOne has advantages, but also disadvantages since they are intrusive. The result is that there are many threats that can be detected, but there are also many false positives. Cortex XDR by Palo Alto Networks is non-intrusive, but in terms of the detail, sometimes potential threats cannot be captured.

What needs improvement?

Cortex XDR by Palo Alto Networks is already good at what they're doing in terms of detections, but I think they should improve their integration capabilities, especially for their XDR capabilities, which are more tied down to their own ecosystems.

For Cortex XDR by Palo Alto Networks to get closer to ten or at least nine, I would like to see more openness in terms of the integrations for their XDR capabilities. The second improvement I would like to see is more into the response and the detection and response capabilities for backups of the system state of the endpoint, such as what we have on SentinelOne.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is more stable than SentinelOne because the detections are not too intrusive.

How are customer service and support?

The technical support by Palo Alto Networks is quite standard, so I think it's acceptable.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

SentinelOne is more complex to operate since they have so many options and rules that can be changed, which can take some time for a SOC analyst to learn about.

How was the initial setup?

Cortex XDR by Palo Alto Networks is easy to implement.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR by Palo Alto Networks is more expensive than SentinelOne right now.

In terms of the average cost of top-tier EDR platforms, I think Cortex XDR by Palo Alto Networks is still reasonable. However, if you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.

What other advice do I have?

Both are almost the same in popularity, but if I can choose one, SentinelOne is quite hyped right now.

They have a representative in Indonesia for both SentinelOne and Cortex XDR by Palo Alto Networks.

Palo Alto Networks has slightly more advantages in terms of the architecture since they have options for their endpoint that cannot connect directly to the internet to have a proxy site, which is something that SentinelOne does not have.

Cortex XDR by Palo Alto Networks is more of a closed system. I have given this review a rating of eight.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Nov 4, 2025
Flag as inappropriate
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
May 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
894,998 professionals have used our research since 2012.
reviewer2798475 - PeerSpot reviewer
Threat Analyst II at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Jan 21, 2026
Centralized monitoring has streamlined threat detection and supported faster incident response
Pros and Cons
  • "Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
  • "I have seen lagging with Cortex XDR by Palo Alto Networks. There was one time when we faced a threat actor trying to gain access to our system. When our team utilized the tool, we were all on the same dashboard and we faced a lag issue at that time of around five minutes, which was quite significant."

What is our primary use case?

We were using Cortex XDR by Palo Alto Networks for different use cases such as Windows login failures, disabled account login failures, and user additions to domain groups. There were multiple use cases that were totally dependent upon the client, including what log ingestions they wanted and what rules they wanted us to apply to it.

What is most valuable?

What I appreciate most about Cortex XDR by Palo Alto Networks is that it has a good tenant feature in which we have multiple tenants. We were working in EU tenants, and apart from this, the GUI is completely easy to understand.

Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most. I would suggest it was a good solution for me.

What needs improvement?

One of the downsides of Cortex XDR by Palo Alto Networks is the KQL language. When I was working as a security analyst using Cortex, there was a disadvantage. People need to have knowledge of the KQL language to understand the fine-tuning of alerts or the creation of new rules. That would be a drawback. Additionally, when investigating a particular alert or case, the complete information is not available in the GUI table if we compare it to other XDRs or other tools.

I would suggest that Cortex XDR by Palo Alto Networks' AI-driven endpoint security would work better. Whenever we are investigating something, the AI would help us by simply writing into a description box. For example, if I want user login information for a particular user, I would write it and the AI would automatically generate all login events from that host. I would suggest that this would be a better feature.

For how long have I used the solution?

I have used Cortex XDR by Palo Alto Networks for around one and a half years.

What do I think about the stability of the solution?

I have seen lagging with Cortex XDR by Palo Alto Networks. There was one time when we faced a threat actor trying to gain access to our system. When our team utilized the tool, we were all on the same dashboard and we faced a lag issue at that time of around five minutes, which was quite significant.

What do I think about the scalability of the solution?

I think scalability for Cortex XDR by Palo Alto Networks is good. I would rate it nine out of ten.

How are customer service and support?

I have contacted Cortex XDR by Palo Alto Networks' technical support because we got stuck somewhere during deployment in our systems on a technical matter. The help was excellent, and I would rate the support a ten out of ten. The support was very good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used CrowdStrike as an alternative to Cortex XDR by Palo Alto Networks.

How was the initial setup?

The deployment of Cortex XDR by Palo Alto Networks is moderate level. I deployed it in my organization last year. You just need a little bit of knowledge, but apart from this, everything is good.

What's my experience with pricing, setup cost, and licensing?

The pricing for Cortex XDR by Palo Alto Networks depends on the organization and the number of endpoints and hosts you are adding, as well as the bandwidth. I cannot specify what the pricing is. However, if you keep it minimal, then it will attract other organizations and you will grab the market.

Which other solutions did I evaluate?

I prefer CrowdStrike more than Cortex XDR by Palo Alto Networks because it has better features. It has a graphical GUI in which if any threats come in, you will have a whole map of it and you can figure out from where the chain of the threat has started. You can check what the initial access was and stop it from there.

What other advice do I have?

I would suggest that Cortex XDR by Palo Alto Networks' agent ability to block more sophisticated or complicated threats in real-time has been effective so far. I have seen that it blocks almost ninety percent of the threats. Sometimes we are left with some IOCs which are zero-day vulnerabilities. In those cases, we have to manually send it to the Cortex XDR by Palo Alto Networks team that manages all the back-end. They filter out the rules, create the workflows, then block all of the things. I would suggest that from one hundred, it works ninety percent of the time.

Cortex XDR by Palo Alto Networks does require maintenance after the deployment on my end. It has requirements. Sometimes we need fine-tuning of the alerts and sometimes we face errors. We occasionally require help when we get stuck somewhere. We reach out to Palo Alto and they help us. The after-service is very good. I would rate this review an eight out of ten overall.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jan 21, 2026
Flag as inappropriate
PeerSpot user
Cyber Security Manager at Welab bank
Real User
Top 10
Dec 19, 2024
Advanced threat detection capabilities provide effective security solutions
Pros and Cons
  • "Cortex XDR features advanced threat detection capabilities."
  • "Cortex XDR is stable, offering high quality and reliable performance."
  • "Cortex XDR could improve its sales support team, including better commission structures and referral programs."
  • "Cortex XDR could improve its sales support team, including better commission structures and referral programs."

What is our primary use case?

I have been working as a cybersecurity manager. I focus on implementing cybersecurity solutions for different companies, and I have hands-on experience working with Cortex XDR solution by Palo Alto Networks.

What is most valuable?

Cortex XDR features advanced threat detection capabilities. The handling GUI allows for advanced searches, rule creation, and local detection. It incorporates AI for normal behavior detection, distinguishing unusual operations. 

These features make the product very effective for threat detection. Additionally, the GUI is user-friendly and the product offers robust AI or normal behavior detection.

What needs improvement?

Cortex XDR could improve its sales support team, including better commission structures and referral programs. Enhancements in marketing and AI features would also be beneficial. It would be advantageous to deploy more rules to the front end and on end-user devices.

For how long have I used the solution?

I have been familiar with Cortex XDR for about three or four years.

What do I think about the stability of the solution?

Cortex XDR is stable, offering high quality and reliable performance. It is consistent and dependable in its operation.

How are customer service and support?

Customer support from Palo Alto Networks is generally adequate. It depends on how I escalate the issue. Every vendor has similar support; it depends on how the case is handled and raised.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I was a reseller for Palo Alto Networks solutions.

I have worked with many different vendors and their products, such as Microsoft Defender, and I am familiar with various cybersecurity solutions from different companies.

What was our ROI?

My customers have reported good ROI since implementing Cortex XDR. They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing. Other companies have not shared similar complaints, and it always pitches itself well to customers.

I'd rate the solution nine out of ten.

What other advice do I have?

I give Cortex XDR a nine out of ten. Although it has a stable and high-quality performance, customer alignment still plays a significant role in the decision-making process.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
NiteshSharma - PeerSpot reviewer
Pre Sales Architect at network techlab
Real User
Top 5Leaderboard
Mar 27, 2025
Automated threat response and behavioral control improve security measures
Pros and Cons
  • "On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine."
  • "I recommend adding a data loss prevention (DLP) solution to Cortex XDR by Palo Alto Networks. The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products."

What is our primary use case?

I work with Cortex XDR by Palo Alto Networks. My primary use involves utilizing its capabilities as a next-generation antivirus solution, providing extended detection and response features along with threat prevention and behavioral control.

What is most valuable?

Cortex XDR by Palo Alto Networks is a good product, serving as a next-generation antivirus with extended detection and response features. It offers threat prevention, behavioral control, automation in threat response, and analytics capabilities, which enhance security measures. The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.

What needs improvement?

I recommend adding a data loss prevention (DLP) solution to Cortex XDR by Palo Alto Networks. The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products. Additionally, multi-tenancy and multi-cloud features are not available and should be considered for inclusion.

For how long have I used the solution?

I have been discussing Cortex XDR by Palo Alto Networks and have utilized its different facets and features in my professional experience.

How are customer service and support?

I have not faced any challenges with the customer support from Palo Alto Networks. Their support is efficient and responsive whenever I raise a ticket through my portal.

How would you rate customer service and support?

Neutral

What was our ROI?

There are good return on investment possibilities from using Cortex XDR by Palo Alto Networks due to its cost-saving compliance features, which can attract customers by reducing expenses and offering comprehensive compliance solutions.

What's my experience with pricing, setup cost, and licensing?

Compared to competitors such as CrowdStrike and Sophos, the pricing of Cortex XDR by Palo Alto Networks is similar to CrowdStrike but more expensive than Sophos. Check Point Harmony, Trend Micro, and Sophos offer lower prices.

Which other solutions did I evaluate?

Competition in the market includes CrowdStrike, Sophos, and Check Point Harmony. They provide similar technology and capabilities like email security, endpoint protection, and DLP solutions in a single console.

What other advice do I have?

On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine. The tool is exceptional in its capabilities, particularly with the Unit 42 feature set and its other integrated options.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
NikhilSharma1 - PeerSpot reviewer
Cyber Engineering Manager @ at a tech vendor with 10,001+ employees
Reseller
Top 20
Jul 26, 2024
Provides comprehensive network visibility and helps us identify threats efficiently
Pros and Cons
  • "The solution's stability is generally good."
  • "The complexity and confusion regarding product variants, such as XDR, Forexiant, and Forexon, must be addressed."

What is our primary use case?

Our primary use case for Cortex XDR is to bridge the gap between a Security Information and Event Management (SIEM) system and an Endpoint Detection and Response (EDR) solution. We use it to fetch data from network devices and endpoints, perform comparisons, and generate alerts. It is useful for detecting impossible travel scenarios where a user's IP address switches rapidly between geographically distant locations, which can indicate VPN use or other anomalies.

What is most valuable?

The product's most valuable feature is the ability to integrate and correlate data from network and endpoint sources. This comprehensive visibility allows us to quickly identify and respond to threats, such as impossible travel scenarios, with greater accuracy and speed.

What needs improvement?

The product could be improved in several areas. The complexity and confusion regarding product variants, such as XDR, Forexiant, and Forexon, must be addressed. There is also a need for clearer differentiation between features and capabilities within Cortex's suite, as the overlap between XDR and XIM can be confusing.

Improvements in the user interface and more intuitive KQL query handling could also enhance usability. Additionally, better support for various deployment scenarios and cost management options would be beneficial.

For how long have I used the solution?

I have been using Cortex for approximately two years.

What do I think about the stability of the solution?

The solution's stability is generally good.

What do I think about the scalability of the solution?

The solution scales well. It is deployed without major issues across 60,000 endpoints in our organization.

How are customer service and support?

Customer support quality varies depending on the support plan. The premium plan offers excellent support. However, if you opt for a standard plan, the level of support may be less satisfactory.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was relatively straightforward. Modern methods, such as pushing clients over port 443, have made deploying endpoints easier than legacy systems.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR is a costly solution.

What other advice do I have?

Overall, Cortex XDR is good software. Ensure you have the financial resources to support the investment or consider alternative solutions if cost is a significant concern.

I rate it a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rehaman Syed - PeerSpot reviewer
Technical Specialist at HCL Technologies
Real User
Top 10
Aug 29, 2024
Provides protection to users against malware along with behavioral threat detection features
Pros and Cons
  • "The product's initial setup phase is very easy."
  • "Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."

What is our primary use case?

I use the solution in my company to protect our clients from unknown malware and threats. We also use the tool in our environment as an antivirus, EDR, and XDR solution.

What is most valuable?

The solution's most valuable feature is that it protects against unknown malware and activities and offers behavioral threat detection functionalities. With a wildcard and based on whatever configurations, it gives alerts and offers an XDR Quick Scan facility. We get proper results from the tool, and after scanning, we can see them on the dashboard.

What needs improvement?

Improvements are required in Cortex XDR agent whenever they are releasing the latest version. Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version. Whenever Palo Alto releases the latest version and when you are deploying the package into the server, we see some disturbances in the CPU usage, like the RAM utilization is more. Generally, the CPU utilization is higher. Disabling one by one component from the profile manager, we are unable to find the exact cause of the issue. When we go to Palo Alto, even after sharing the logs and mentioning the issue, the solution team comes back and gives us some more versions of the tool. If Cortex XDR Agent 8.4.0 is having issues, then the tool's team offers us Cortex XDR Agent 8.4.1. Some updates can update the tool to the latest version.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for eighteen months. I use Cortex XDR 8.4.0. I am a user of the tool.

What do I think about the stability of the solution?

It is a stable solution. The tool doesn't have bugs.

What do I think about the scalability of the solution?

The tool is used by three members who are supporting 5,000 desktops, including workstations and servers.

How are customer service and support?

I haven't directly contacted the solution's technical support much, but I have reached out to them via email. I called the tool's support team twice, and during the call, we discussed some troubleshooting steps. I am happy with the tool's support.

Which solution did I use previously and why did I switch?

When I joined my current company, I saw that the tool was being used. I don't work directly for the company. I have clients and I support Cortex XDR agents for them.

How was the initial setup?

The product's initial setup phase is very easy.

The solution is deployed on an on-premises model.

What other advice do I have?

I recommend the tool to first-time users. Before using Cortex XDR agent, the previous antivirus and EDR solution needs to be set with the new or the latest Cortex XDR agent, especially the policies.

The tool is easy to learn, understand, and manage with a one-day training session compared to other products.

I rate the tool a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Bandi Rakesh - PeerSpot reviewer
Cyber Security Analyst at HALA INFOSEC
Real User
Top 20
Sep 1, 2024
Helps find bugs and prevents attacks by hackers
Pros and Cons
  • "The solution helps find bugs, and it is safe to use to prevent attacks by hackers."
  • "The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content."

What is our primary use case?

We use the solution to deduct from the endpoints any files in the network or any suspicious thing happening in the host machine or servers. We have the Palo Alto Networks Firewall team, and we check the connection from the Palo Alto Networks Firewalls using Cortex XDR by collecting all the information.

What is most valuable?

The best thing about Cortex XDR is that it has host servers, networks, and proxy servers. On the other hand, CrowdStrike has only hosts and servers. The solution helps find bugs, and it is safe to use to prevent attacks by hackers.

What needs improvement?

The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content. We can even block the IP address in malicious content. If any host is affected, we can isolate the host, rectify that problem, and prevent it from happening in the future.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for one year.

What do I think about the scalability of the solution?

More than 15,000 people are using the solution in our organization.

How are customer service and support?

We contacted the technical support team for a downgrade issue with Cortex XDR. Due to some network errors, we worked with the support team. They rectified the problem, but it affected us for over two hours. We had to check all the hosts and servers connected to Cortex XDR. We rechecked and reinstalled Cortex XDR. I was happy with the support team’s fast response time.

Which solution did I use previously and why did I switch?

We are also using CrowdStrike. Compared to CrowdStrike, Cortex XDR gives more detailed information for us to work with. We can connect to the host's live terminal, work with that host in an emergency, and prevent that host.

How was the initial setup?

The solution's ease of deployment depends on the user's experience. It would be easy for someone with experience.

What's my experience with pricing, setup cost, and licensing?

Compared to CrowdStrike, Cortex XDR is an expensive solution.

What other advice do I have?

A beginner will take some time to learn to use the solution. I would recommend the solution to other users.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.