We use the product as a detection and response application.
Business development manager for Palo Alto Networks at Westcon-Comstor
Has a simple setup process and efficient stability
Pros and Cons
- "The product's most valuable features are massive user and feature intelligence exploit detection."
- "It is an enterprise-level solution. Its price could be less expensive."
What is our primary use case?
What is most valuable?
The product's most valuable features are massive user and feature intelligence exploit detection. It is very useful in detecting threats to databases. The last meter statistics prove the efficient capabilities of the solution.
What needs improvement?
It is an enterprise-level solution. Its price could be less expensive.
For how long have I used the solution?
We have been using Cortex XDR by Palo Alto Networks for three years.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is 100% stable. I have never received any complaints from the customers.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is easily scalable as it is a cloud-based product.
How are customer service and support?
We provide support services for our customers. Palo Alto's support services are expensive, and customers also encounter language barriers.
How was the initial setup?
The initial process is simple. It requires training of about three to four days to understand the installation process. It is deployed on the cloud. The number of software engineers required depends on the number of the endpoints.
What's my experience with pricing, setup cost, and licensing?
We pay in advance for the product's license. It has reasonable pricing for the use cases it provides to the company. We can split this payment monthly, quarterly, or yearly, according to the customer's requirements. For a cost-benefit analysis when choosing a security solution, consider factors such as the number of attacks prevented, the impact of those attacks, potential losses, and other hidden costs.
What other advice do I have?
I rate Cortex XDR by Palo Alto Networks for ten out of ten. It could be improved from a commercial perspective. It could approach the SMB market as well.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Cash Management Officer at a retailer with 1,001-5,000 employees
Lightweight, helpful technical support, and user-friendly
Pros and Cons
- "The solution's most valuable feature is its ability to rapidly detect certain hardware files."
- "Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
What is our primary use case?
Cortex XDR by Palo Alto Networks is the antivirus solution we use for Androids.
What is most valuable?
The solution's most valuable feature is its ability to rapidly detect certain hardware files.
All other features of Cortex XDR by Palo Alto Networks are fine.
What needs improvement?
We have implemented a product that blocks USB usage and also provides device control for our company.
Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities.
Although we are using this feature, we allow specific systems and USB devices. For example, we enable certain users to use external hard drives but we may disable them if necessary. However, due to the nature of our organization, we do not have a dedicated department for this task.
For how long have I used the solution?
I have been working with Cortex XDR by Palo Alto Networks for approximately seven years.
We are working with the most recent version.
What do I think about the stability of the solution?
The stability of Cortex XDR by Palo Alto Networks is a nine out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of Cortex XDR by Palo Alto Networks a ten out of ten.
In our organization, we have 2,700 licenses. Our users are mostly IT specialists.
Our organization is using the Cortex system across all platforms, including servers running Linux, Mac, and Windows operating systems.
Maintenance is done by the vendor.
How are customer service and support?
Technical support is good.
We have also used them for Palo Alto Firewalls.
We do not have any issues with support, I would rate them a nine out of ten.
Which solution did I use previously and why did I switch?
Previously, approximately one year ago, we used Kaspersky.
We are currently using both Kaspersky and Cortex XDR by Palo Alto Networks.
How was the initial setup?
The installation process is straightforward, and the software itself is lightweight.
What about the implementation team?
The installation process takes less than a minute.
What's my experience with pricing, setup cost, and licensing?
Our license will require renewal in August, after which the maintenance will continue as usual.
I am not aware of the fees, it is handled by our financial department.
What other advice do I have?
I would recommend this solution to others who are interested in using it.
I would rate Cortex XDR by Palo Alto Networks nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
June 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Network Security Engineer at I Dream networks pvt ltd
A useful solution to combat the growing cyberattacks
Pros and Cons
- "The solution allows control over the user and his machine through Cortex XDR security policies."
- "Palo Alto Networks Cortex XDR does not detect malicious activity like in other anti-virus solutions like Trend Micro and Windows with Cisco."
What is our primary use case?
Cortex XDR is an artificial intelligence-based solution that automatically detects malicious activity performed by users or user machines, blocking it with the help of AI. We also create security policies on Cortex XDR that can be managed by Cortex XDR. Let's say that a company wants a security policy to work for a home user or VPN client user. It also includes an enterprise network at home.
What is most valuable?
User control in Cortex XDR allows users to restrict access to certain websites from a company laptop used over a home network. The solution allows control over the user and his machine through Cortex XDR security policies.
What needs improvement?
Cortex XDR is not that smart compared to Check Point. We also deal with Check Point. Check Point solutions, Check Point Firewall, Check Point solution WAF technology, or anti-virus technology can be considered smart because of Palo Alto. The detection of malicious activities performed by Check Point is good. Artificial intelligence is not a good match for Check Point because sometimes Palo Alto Networks Cortex XDR does not detect malicious activity like in other anti-virus solutions like Trend Micro and Windows with Cisco.
I also want a better detection feature like the one in Check Point and any other anti-virus, for a matter of fact.
For how long have I used the solution?
I am a consultant for the solution. I work with Palo Alto, our solution provider, and offer Cortex solutions and Palo Alto firewalls. We also sell Cortex XDR at Mac Global. It has been approximately six months to a year since I started working with this solution. Speaking about the version, it is the Cortex XDR client. Our responsibilities are centered around the client-based solution, including managing clients and installing software and rules. Palo Alto’s team manages the other aspects of the solution.
What do I think about the stability of the solution?
It is a stable solution since it is on the cloud. CPU utilization and hardware requirements are not necessary. According to some user licenses, when we purchase them, we get much utilization of hardware requirements through the cloud.
What do I think about the scalability of the solution?
Cortex XDR is a scalable solution with around 500 to 600 users. User visibility, user policy, and security policy can be implemented in one view on Cortex XDR. The approximate number of clients constantly using Cortex XDR is between 200 to 250.
How are customer service and support?
I am working with iDream Networks, and we are partners of Palo Alto Networks.
How was the initial setup?
I will give 50 out of 100 points since the setup of Cortex XDR is neither too easy nor too difficult to implement. Its dashboard is very easy to manage since no other sites need to be opened to manage it. Also, it can be managed from anywhere. I am not involved in the deployment process as I only manage the solution.
What about the implementation team?
The configuration and implementation are done by Palo Alto’s team.
What's my experience with pricing, setup cost, and licensing?
Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis.
What other advice do I have?
I recommend Palo Alto Networks Cortex XDR as a dependable option for future requirements. Cyberattacks are on the rise, and so that's why I have Palo Alto’s XDR. I also suggest Palo Alto Networks Cortex XDR to all customers. On a scale of 100, I rate this solution at 85, and on a scale of one to ten, I give it an eight.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Used for investigating incidents and malware analysis
Pros and Cons
- "The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device."
- "It takes time to scan the servers and devices."
What is our primary use case?
I used the solution for investigating incidents and malware analysis.
What is most valuable?
The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device. For investigation, we can just drop down and easily elaborate on the issues, like where the user went and what they downloaded. We can use the solution to find out everything easily.
What needs improvement?
It takes time to scan the servers and devices. Scanning the server sometimes takes two to three days. If the device is offline, the scan gets disconnected.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for one and a half years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is a stable solution.
What do I think about the scalability of the solution?
Around seven people used the solution in our organization.
What's my experience with pricing, setup cost, and licensing?
Cortex XDR by Palo Alto Networks is quite an expensive solution.
What other advice do I have?
I use the solution for investigation, which includes incident handling and incident alerts. There is a separate part in Cortex XDR where we can use timestamps to categorize the alert or attack type. Based on the attack criticality, we can investigate and fine-tune a lot of things. In Cortex XDR, we can get the same alert at different times. We can fine-tune using the Cortex XDR tool.
Also, we can use queries in Cortex XDR for automation, accessing the device, or scanning the device. The query part is good, but we need to spend a little time learning about the query. It's easy to understand the query.
There is a template that you can use to click and say something. If you are going to investigate, many tabs are given based on the tactics, techniques, and procedures. It is easy to understand, and we can gather basic information from there. It is easy for a new user to learn to use the solution for the first time.
Overall, I rate the solution ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Network Engineer at a construction company with 10,001+ employees
Low system resource usage, reliable, and flexible
Pros and Cons
- "The most valuable feature of Cortex XDR by Palo Alto Networks is the low consumption of system resources. The solution uses a lot of AI and machine learning."
- "Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it."
What is our primary use case?
We are using Cortex XDR by Palo Alto Networks for all of our remote users because they are not connected to our on-premise data center.
What is most valuable?
The most valuable feature of Cortex XDR by Palo Alto Networks is the low consumption of system resources. The solution uses a lot of AI and machine learning.
What needs improvement?
Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately two years.
What do I think about the stability of the solution?
Cortex XDR by Palo Alto Networks is stable.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is scalable. add license and add many clients.
We have approximately 300 users using this solution in my company.
How are customer service and support?
I have not had an issue to need the support.
Which solution did I use previously and why did I switch?
We have previously used antivirus solutions. We decided to use Cortex XDR by Palo Alto Networks because of its flexibility.
How was the initial setup?
The initial setup of Cortex XDR by Palo Alto Networks is straightforward because it is in the cloud. The whole deployment took approximately one day.
I rate the setup of Cortex XDR by Palo Alto Networks a four out of five.
What about the implementation team?
We used the vendor to do the implementation of the solution.
What other advice do I have?
After the deployment of this solution, there is no need for maintenance.
I recommend this solution to others because it is easy to manage, reliable, and overall good to use.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Associate at HTH Global Network
Great threat detection capabilities and good internal threat intelligence
Pros and Cons
- "Has great threat detection capabilities."
- "The encryption is not up to the mark."
What is our primary use case?
This solution is a next-generation antivirus with more advanced capability and security. We have a partnership with Palo Alto.
What is most valuable?
Cortex XDR is very easy to deploy and has great threat detection capabilities and good internal threat intelligence.
It uses advanced AI analytics, behavior analytics, and custom-made detection to detect advanced threats before they occur.
If a customer says it's expensive- let's say I will say no it is not. Other values are added then it is more reasonable having strong features.
With a click, I can access the system and isolate it from other networks, and then go into a further forensic investigation of the current threat without compromising anything else.
Its stitches with external logs are perfect and enhanced.
What needs improvement?
1. Disk Encryption capability.
2. User group-wise admin role. They have module-wise roles but a user group-wise role is not available.
For how long have I used the solution?
We've been supplying this solution to customers for two years.
What do I think about the stability of the solution?
I have found this solution as NG AV is most stable compare with other solution
What do I think about the scalability of the solution?
The scalability is perfect.
How was the initial setup?
The initial setup is very easy.
What about the implementation team?
We implemented the solution with a vendor team, HTH Global Network. Their expertise is an eight out of ten.
What other advice do I have?
I recommend this solution, it works well and I rate it a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Owner and Executive Director at Cloud 9 s.r.o.
Good features, strong protection, and very scalable and stable
Pros and Cons
- "Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
- "It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
What is our primary use case?
It's mainly for protection against malware. We work very closely with a major partner of Palo Alto in the Czech Republic, and we have experience with the whole XDR solution. It's very useful for us and a very capable solution.
How has it helped my organization?
Clients have a big problem with phishing campaigns and phishing attacks. Cortex XDR provides some level of protection against malware spreading in the network with a wrong click of users.
What is most valuable?
Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection.
What needs improvement?
Its price is too high. That's a big problem for customers.
It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system.
In terms of additional features, there is very strong development. I have seen the roadmap, and we will see what happens. The roadmap looks nice, but it's still more of a network security solution than a content-security solution. The development in network security is quite strong. I'm very happy with that, but if a customer would like to implement a zero-trust security concept, it's necessary to combine this solution with other vendors. There is some part of the integration that is not so easy because you have to integrate rules and some features. It's not so automatic in network communication. You have to make some appropriate automation there, or you have to do it manually. It's time-consuming and it's also expensive.
For how long have I used the solution?
I have been using it from the beginning. It has been more than six years.
What do I think about the stability of the solution?
It's a very stable solution. I would rate it a nine out of ten in terms of stability.
What do I think about the scalability of the solution?
It's a very scalable solution. If you compare it with a SIEM solution from Palo Alto, it's very powerful. I would rate it a nine out of ten in terms of scalability. It's definitely for enterprises.
How are customer service and support?
Their technical support is not bad, but sometimes, when we have some issues, the support teams from Europe or Central Europe are not able to help us. We have to escalate the issue somewhere else, such as to the US. They have a very strong support team there, but it's time-consuming. Sometimes, it takes them days or weeks to solve some tricky problems, but their support for standard issues is okay. There is a very good response, but for a technical issue, it's sometimes more difficult. I would rate their support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I also worked a little bit with SentinelOne. Cortex XDR is very similar to the SentinelOne solution from the features point of view. It's a little bit different technology, but both solutions are very capable.
How was the initial setup?
It's somewhere in the middle. It's not for beginners, but if you know what to do, it's quite easy.
It's a cloud-based solution, which sometimes is an issue for customers. In the past, it was on-prem, but Palo Alto decided to change the policy and everything is cloud-based or located in the cloud. It's not a security problem from my point of view, but a few customers feel uncomfortable with sending data to the cloud and back.
What about the implementation team?
Very often, it's an in-house implementation.
What's my experience with pricing, setup cost, and licensing?
It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing.
What other advice do I have?
Overall, I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Site administrator officer at a tech services company with 11-50 employees
Effective machine learning capabilities, responsive support, and easy to understand
Pros and Cons
- "The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
- "Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
What is our primary use case?
Cortex XDR is used for monitoring and securing large numbers of endpoints, typically in the range of 5,000 to 10,000. It is considered to be an effective solution for mitigating security risks in these environments.
What is most valuable?
The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions.
What needs improvement?
Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it.
For how long have I used the solution?
I have been using Cortex XDR by Palo Alto Networks for approximately four months.
What do I think about the stability of the solution?
The solution is stable.
I rate the stability of Cortex XDR by Palo Alto Networks an eight out of ten.
What do I think about the scalability of the solution?
Cortex XDR by Palo Alto Networks is a highly scalable solution.
I rate the scalability of Cortex XDR by Palo Alto Networks an eight out of ten.
How are customer service and support?
The support team at Cortex XDR by Palo Alto Networks is very responsive and helpful in addressing any issues or challenges that may arise. They are highly accessible and knowledgeable about the products they offer. Overall, I have been very satisfied with the support provided by Palo Alto while deploying their solutions.
Which solution did I use previously and why did I switch?
We previously used CrowdStrike Falcon X.
Cortex XDR by Palo Alto Networks is easier to understand and use compared to CrowdStrike Falcon X endpoint. The dashboard and interface of CrowdStrike Falcon X can be cluttered, making it difficult for some users to understand where to begin when it comes to incident response or threat hunting. In contrast, Cortex XDR by Palo Alto Networks is simple to navigate and understand.
How was the initial setup?
The initial setup of the solution can take approximately one hour. One hour is the longest it has ever taken us for the setup. We have not had an issue with the setup.
I rate the initial setup of Cortex XDR by Palo Alto Networks a seven out of ten.
What about the implementation team?
We do the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help.
Customers tend to rather have a less expensive solution than the best one.
I rate the price of Cortex XDR by Palo Alto Networks an eight out of ten.
What other advice do I have?
We are using two engineers for the maintenance of the solution.
In our market here in Malaysia, the solution is perceived as being of high quality and providing good service.
I would recommend this solution to others, it is a good solution. It is my job to recommend solutions.
I rate Cortex XDR by Palo Alto Networks an eight out of ten.
The solution is not perfect and that is why I gave the rating of eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Extended Detection and Response (XDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Microsoft Sentinel
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Trend Vision One Endpoint Security
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?