What is our primary use case?
Our company uses the solution for endpoint protection, detection, and response. The solution has antivirus and EDR capabilities. Our SOC analysts use it to investigate incidents. We currently have 300 to 400 users with two admins for management. The solution is installed on all user laptops to protect workstations.
We also implement the solution for customers as a service. Most customers buy the solution for registry reasons and compliance standards. It gives you all the compliance points and improves how your SOC functions because it provides comprehensive visibility over the entire network and endpoints. It is called XDR because it not only looks at endpoints but also network traffic.
The solution is offered on Palo Alto's private network. I think the underlying provider is Google Cloud, but that doesn't really matter. You are asked the region of your instance for connection such as Europe or the Middle East.
What is most valuable?
The solution perfectly correlates with Palo Alto's Networks Firewall to perform XDR capabilities such as network traffic plus endpoint security. This is what distinguishes the solution from other products.
From a single pane of glass, you can easily manage all of your endpoints.
The dashboard is intuitive so you can easily investigate or track incidents.
The solution has a fair amount of integrations with certain intelligence tools or third-party products.
What needs improvement?
The solution should force customers to integrate with network traffic to see the full benefits of XDR. If you are not integrating it or feeding in your network traffic, then you are just buying a normal antivirus which doesn't make any sense. You are paying double the price to use the antivirus feature or to say you have XDR, but in reality you are not using it.
The solution should include an on-premises option because some customers want only on-premises. It would be hard, but good to do if possible.
Open XDR would be beneficial in the future. Right now, the solution is Closed XDR so cannot communicate with the few new vendors in the Open XDR market.
For how long have I used the solution?
I have been using the solution more than two years.
The solution used to be called Traps when it was on-premises only. It was rebranded as Cortex XDR when it became a cloud solution.
What do I think about the stability of the solution?
The solution is stable so I rate stability a nine out of ten.
What do I think about the scalability of the solution?
The solution is very scalable. You can have 500 users and scale tomorrow to 10,000 with no extra work but just purchasing the licenses needed.
I rate scalability a ten out of ten.
How are customer service and support?
The level of support fluctuates but on average is rated an eight out of ten.
How was the initial setup?
The setup is very easy because it is a cloud solution. You just log in and use it immediately. I rate setup a nine out of ten.
What about the implementation team?
We are a third-party integrator and implement the solution for customers. One staff person can handle an implementation.
As a customer, you receive a link which is your tenant for login. From there, deployment time is just how long it takes to get the installer agent and put on all of your endpoints. For example, if you are a corporation that has 300 laptops, then you install the agent on each and every server.
You will need about three hours to configure the solution and then it is up to your admins to install the agent on all endpoints. There is usually a way to automatically install agents from the Active Directory or other tools.
You need to integrate your network traffic to the XDR itself. If you have a Palo Alto Firewall, it is easy to navigate through integration. If you have FortiGate or Cisco firewalls, then you can configure the firewall to send the log to the cloud. It is sometimes hard to convince customers to send or keep their logs on the cloud.
What's my experience with pricing, setup cost, and licensing?
The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version.
The solution is neither inexpensive nor expensive, so I rate pricing a three out of ten.
Which other solutions did I evaluate?
Nowadays, CrowdStrike, Cortex XDR, and the solution are rebranding and selling their products as XDR. Everyone hears about antivirus but now XDR is available to protect endpoints and get intelligence from the network.
Most customers who have an XDR product only use the antivirus features. They are not correlating the network traffic with the XDR itself, so they are not getting the full benefit.
The solution does not force you to correlate so you can use it without integrating with your network. But again, this is not how XDR is supposed to work.
For example, if you buy a Bugatti but only drive it at 80 kilometers per hour, then you should just go and buy a Nissan. If you buy XDR but do not integrate it with your network traffic, then you just have a Nissan antivirus.
What other advice do I have?
I recommend the solution and rate it a ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company has a business relationship with this vendor other than being a customer.