No more typing reviews! Try our Samantha, our new voice AI agent.
Senior System Administrator at a government with 10,001+ employees
Real User
Jun 1, 2022
Makes it easy to isolate endpoints and lets us know if something needs to be addressed
Pros and Cons
  • "Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them."
  • "I don't have to do much monitoring with it; I don't have to have anybody manually looking at this, it gives us reports, and it lets us know if something needs to be addressed, and we can easily address it."
  • "We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
  • "We had a problem with getting our older endpoints up to date, but their newest updates have been really good."

What is our primary use case?

We use it to make sure that our antivirus is up to par. 

It used to be on-prem, but now, it's completely on the cloud. In terms of the version, we've got some old endpoints that we had to manually bring up to date, but for the most part, it's up to date.

How has it helped my organization?

I don't have to do much monitoring with it. I don't have to have anybody manually looking at this. It gives us reports, and it lets us know if something needs to be addressed, and we can easily address it. I've been pleased with it. It's been a really good product for us.

What is most valuable?

Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them. The hash that they use is pretty comprehensive. I like WildFire. It gives us a better idea of what is a true virus and what is a false positive.

What needs improvement?

We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do.

Buyer's Guide
Cortex XDR by Palo Alto Networks
March 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

For how long have I used the solution?

We've been using it for at least three years.

What do I think about the stability of the solution?

It has been stable. I have not had any issues with it.

What do I think about the scalability of the solution?

For our use, we didn't need scalability with it. It has just been working as we needed it to work.

How are customer service and support?

The only time we had to deal with their support was when we had a problem with getting our older endpoints up to date. They made the upgrades and gave us the solutions on what we needed to do, and that has been working for us. 

How was the initial setup?

It was pretty straightforward, and now that it does an automatic update, I don't even have to remember to update it anymore. Once a definition expires, it automatically goes in and puts in the newest definitions, and updates all the endpoints. It is way better than what it used to be.

What's my experience with pricing, setup cost, and licensing?

I don't recall what the cost was, but it wasn't really that expensive.

What other advice do I have?

The only thing I would advise is to get a solution for which you don't have to do a lot of monitoring. It helps when we don't have to have an extra person to manually go through and look at each endpoint to make sure things are up to date and all definitions are up to date. 

I would rate it a nine out of ten because it's a really stable platform, and it is doing everything that I need it to do. You can always have improvement, but I'm really not sure what that improvement would be.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Rustam-Rustamli - PeerSpot reviewer
CISO at International Bank of Azerbaijan
Real User
May 23, 2022
Provides great security with its machine-learning technology and behavior-based analytics features
Pros and Cons
  • "Palo Alto is constantly adding new features."
  • "These days it's machine-learning technology and behavior-based analytics features that make us more secure."
  • "The solution lacks real-time, on-demand antivirus."
  • "There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state."

What is our primary use case?

This solution has replaced our traditional antivirus solutions; it protects our environment and safeguards our endpoints from any malware or exploitation. We are based in Azerbaijan, I'm the CISO of the company and we are customers of Palo Alto. 

How has it helped my organization?

We've seen benefits because the solution includes a big data approach to cyber security. All information is collected from the network, the endpoints, and the logs and analyzed by applying a big-data approach that shows up anomalies. 

What is most valuable?

I chose this solution because they constantly add new features and are very proactive about that. To my mind, signature-based antivirus is a thing of the past. These days it's machine-learning technology and behavior-based analytics features that make us more secure. XDR feels secure because of those features.

What needs improvement?

There are still a few gaps with this solution. For example, real-time, on-demand antivirus is not there. If you're looking for compliance XDR is somewhat lacking. There is also no recovery feature; if some endpoint is under attack there must be the possibility of recovering it or restoring it to a normal state. That is currently lacking in XDR. 

For how long have I used the solution?

I've been using this solution for about two years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

This solution is scalable. 

How are customer service and support?

We have premium Palo Alto support and they provide good service. 

How was the initial setup?

The initial setup is straightforward. 

What other advice do I have?

I think any XDR technology is best for protecting an environment from cyber attacks. The visibility it provides is crucial and XDR gives us that, we can see all effect vectors. 

I rate this solution eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Cortex XDR by Palo Alto Networks
March 2026
Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
Shibin V. - PeerSpot reviewer
Senior Security Engineer at Gadgeon Systems Inc.
Real User
Top 5
Jul 13, 2024
Used for investigating incidents and malware analysis
Pros and Cons
  • "The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device."
  • "It takes time to scan the servers and devices."

What is our primary use case?

I used the solution for investigating incidents and malware analysis.

What is most valuable?

The solution allows us to gain remote access without the user's knowledge and take the necessary actions on the device. For investigation, we can just drop down and easily elaborate on the issues, like where the user went and what they downloaded. We can use the solution to find out everything easily.

What needs improvement?

It takes time to scan the servers and devices. Scanning the server sometimes takes two to three days. If the device is offline, the scan gets disconnected.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for one and a half years.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks is a stable solution.

What do I think about the scalability of the solution?

Around seven people used the solution in our organization.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR by Palo Alto Networks is quite an expensive solution.

What other advice do I have?

I use the solution for investigation, which includes incident handling and incident alerts. There is a separate part in Cortex XDR where we can use timestamps to categorize the alert or attack type. Based on the attack criticality, we can investigate and fine-tune a lot of things. In Cortex XDR, we can get the same alert at different times. We can fine-tune using the Cortex XDR tool.

Also, we can use queries in Cortex XDR for automation, accessing the device, or scanning the device. The query part is good, but we need to spend a little time learning about the query. It's easy to understand the query.

There is a template that you can use to click and say something. If you are going to investigate, many tabs are given based on the tactics, techniques, and procedures. It is easy to understand, and we can gather basic information from there. It is easy for a new user to learn to use the solution for the first time.

Overall, I rate the solution ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ragesh Singh - PeerSpot reviewer
Cyber Security Engineer at ACPL
Real User
May 17, 2023
Performs stitching between a number of security domains
Pros and Cons
  • "We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
  • "Cortex XDR should have a lightweight agent, and the agent size should not be heavy."

What is our primary use case?

Cortex XDR does the stitching between a number of security domains, like email security, API security, and web security. The solution does the stitching from different sources and makes a logical incident.

What is most valuable?

We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action. We don't need to navigate different solutions and tools or use our human intelligence to correlate all the information to make the logic. Cortex XDR entirely does it, and we can take action.

What needs improvement?

Cortex XDR should have a lightweight agent, and the agent size should not be heavy. Cortex XDR’s technical support should also be improved.

Cortex XDR should provide a feature to remove or uninstall an agent directly from the console itself without the help of an IT engineer. No one wants to do a manual installation of the agent. Everyone is looking for a solution to remove the agent from the console directly.

For how long have I used the solution?

I have been working with Cortex XDR by Palo Alto Networks for two years.

What do I think about the stability of the solution?

I rate Cortex XDR a ten out of ten for stability.

What do I think about the scalability of the solution?

I rate Cortex XDR a five out of ten for scalability.

How are customer service and support?

The technical support of Cortex XDR and other OEM products is not very good. Cortex XDR's technical support does not usually respond quickly.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate Cortex XDR’s initial setup an eight out of ten.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR’s pricing is very reasonable. I rate Cortex XDR a five out of ten for pricing.

What other advice do I have?

I am using the latest version of Cortex XDR by Palo Alto Networks. Cortex XDR is usually deployed in our clients’ organization on cloud. The time it takes to deploy Cortex XDR depends totally upon the organization.

The biggest drawback of Cortex XDR is that it has a heavyweight agent. Cortex XDR would be a good product if this issue could be resolved.

Overall, I rate Cortex XDR an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
MartinPulpan - PeerSpot reviewer
Owner and Executive Director at Cloud 9 s.r.o.
Real User
Jan 31, 2023
Good features, strong protection, and very scalable and stable
Pros and Cons
  • "Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection."
  • "It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."

What is our primary use case?

It's mainly for protection against malware. We work very closely with a major partner of Palo Alto in the Czech Republic, and we have experience with the whole XDR solution. It's very useful for us and a very capable solution.

How has it helped my organization?

Clients have a big problem with phishing campaigns and phishing attacks. Cortex XDR provides some level of protection against malware spreading in the network with a wrong click of users.

What is most valuable?

Cortex XDR is a very capable solution for protecting large networks and a lot of endpoints. It's very useful because the automation is very high, and if you combine it with the features on Palo Alto firewalls, it provides very strong protection.

What needs improvement?

Its price is too high. That's a big problem for customers.

It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system.

In terms of additional features, there is very strong development. I have seen the roadmap, and we will see what happens. The roadmap looks nice, but it's still more of a network security solution than a content-security solution. The development in network security is quite strong. I'm very happy with that, but if a customer would like to implement a zero-trust security concept, it's necessary to combine this solution with other vendors. There is some part of the integration that is not so easy because you have to integrate rules and some features. It's not so automatic in network communication. You have to make some appropriate automation there, or you have to do it manually. It's time-consuming and it's also expensive.

For how long have I used the solution?

I have been using it from the beginning. It has been more than six years.

What do I think about the stability of the solution?

It's a very stable solution. I would rate it a nine out of ten in terms of stability.

What do I think about the scalability of the solution?

It's a very scalable solution. If you compare it with a SIEM solution from Palo Alto, it's very powerful. I would rate it a nine out of ten in terms of scalability. It's definitely for enterprises.

How are customer service and support?

Their technical support is not bad, but sometimes, when we have some issues, the support teams from Europe or Central Europe are not able to help us. We have to escalate the issue somewhere else, such as to the US. They have a very strong support team there, but it's time-consuming. Sometimes, it takes them days or weeks to solve some tricky problems, but their support for standard issues is okay. There is a very good response, but for a technical issue, it's sometimes more difficult. I would rate their support a seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I also worked a little bit with SentinelOne. Cortex XDR is very similar to the SentinelOne solution from the features point of view. It's a little bit different technology, but both solutions are very capable.

How was the initial setup?

It's somewhere in the middle. It's not for beginners, but if you know what to do, it's quite easy.

It's a cloud-based solution, which sometimes is an issue for customers. In the past, it was on-prem, but Palo Alto decided to change the policy and everything is cloud-based or located in the cloud. It's not a security problem from my point of view, but a few customers feel uncomfortable with sending data to the cloud and back.

What about the implementation team?

Very often, it's an in-house implementation.

What's my experience with pricing, setup cost, and licensing?

It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing.

What other advice do I have?

Overall, I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kamil Fahmi - PeerSpot reviewer
Site administrator officer at a tech services company with 11-50 employees
Real User
Jan 18, 2023
Effective machine learning capabilities, responsive support, and easy to understand
Pros and Cons
  • "The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
  • "Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."

What is our primary use case?

Cortex XDR is used for monitoring and securing large numbers of endpoints, typically in the range of 5,000 to 10,000. It is considered to be an effective solution for mitigating security risks in these environments.

What is most valuable?

The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions.

What needs improvement?

Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it.

For how long have I used the solution?

I have been using Cortex XDR by Palo Alto Networks for approximately four months.

What do I think about the stability of the solution?

The solution is stable.

I rate the stability of Cortex XDR by Palo Alto Networks an eight out of ten.

What do I think about the scalability of the solution?

Cortex XDR by Palo Alto Networks is a highly scalable solution.

I rate the scalability of Cortex XDR by Palo Alto Networks an eight out of ten.

How are customer service and support?

The support team at Cortex XDR by Palo Alto Networks is very responsive and helpful in addressing any issues or challenges that may arise. They are highly accessible and knowledgeable about the products they offer. Overall, I have been very satisfied with the support provided by Palo Alto while deploying their solutions.

Which solution did I use previously and why did I switch?

We previously used CrowdStrike Falcon X.

Cortex XDR by Palo Alto Networks is easier to understand and use compared to CrowdStrike Falcon X endpoint. The dashboard and interface of CrowdStrike Falcon X can be cluttered, making it difficult for some users to understand where to begin when it comes to incident response or threat hunting. In contrast, Cortex XDR by Palo Alto Networks is simple to navigate and understand.

How was the initial setup?

The initial setup of the solution can take approximately one hour. One hour is the longest it has ever taken us for the setup. We have not had an issue with the setup.

I rate the initial setup of Cortex XDR by Palo Alto Networks a seven out of ten.

What about the implementation team?

We do the implementation of the solution.

What's my experience with pricing, setup cost, and licensing?

The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help.

Customers tend to rather have a less expensive solution than the best one.

I rate the price of Cortex XDR by Palo Alto Networks an eight out of ten.

What other advice do I have?

We are using two engineers for the maintenance of the solution.

In our market here in Malaysia, the solution is perceived as being of high quality and providing good service. 

I would recommend this solution to others, it is a good solution. It is my job to recommend solutions.

I rate Cortex XDR by Palo Alto Networks an eight out of ten.

The solution is not perfect and that is why I gave the rating of eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Dennis Ngetich - PeerSpot reviewer
Cloud Specialist at Eazzy Solutions
Reseller
Aug 9, 2022
Scalable and high availability
Pros and Cons
  • "Cortex XDR by Palo Alto Networks should be a stable solution."
  • "The scalability of Cortex XDR by Palo Alto Networks is very good."
  • "Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."
  • "Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console."

What is our primary use case?

Cortex XDR by Palo Alto Networks is a network management solution.

What needs improvement?

Cortex XDR by Palo Alto Networks can improve mobile integration to allow access to the console.

For how long have I used the solution?

I have sold Cortex XDR by Palo Alto Networks within the last 12 months.

What do I think about the stability of the solution?

Cortex XDR by Palo Alto Networks should be a stable solution.

What do I think about the scalability of the solution?

The scalability of Cortex XDR by Palo Alto Networks is very good.

What's my experience with pricing, setup cost, and licensing?

The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month.

What other advice do I have?

I would recommend this solution to others.

I rate Cortex XDR by Palo Alto Networks an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Jitendra_Singh - PeerSpot reviewer
Senior Vice President at Chi Networks
Real User
Top 5
Jul 6, 2022
Helps to secure your infrastructure
Pros and Cons
  • "Cortex XDR's most valuable feature is its intelligence-based dashboards."
  • "Cortex XDR alerts us on the dashboard when there's a threat, which allows us to restrict that user and helps secure our infrastructure."
  • "Cortex XDR could be improved with more GUI features."
  • "Cortex XDR could be improved with more GUI features."

What is our primary use case?

I primarily use Cortex XDR to protect end-users from ransomware, malware, spam, and phishing.

How has it helped my organization?

Cortex XDR alerts us on the dashboard when there's a threat, which allows us to restrict that user and helps secure our infrastructure.

What is most valuable?

Cortex XDR's most valuable feature is its intelligence-based dashboards.

What needs improvement?

Cortex XDR could be improved with more GUI features.

For how long have I used the solution?

I've been using Cortex XDR for a year.

What do I think about the stability of the solution?

Cortex XDR is quite stable.

What do I think about the scalability of the solution?

Cortex XDR is scalable.

How are customer service and support?

Cortex XDR's technical support is really good, though their knowledge of endpoint protection could be deeper.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was quite straightforward, and deployment took two to three days.

What about the implementation team?

We used an in-house team.

What's my experience with pricing, setup cost, and licensing?

Cortex XDR's pricing is ok. We pay about $20 a year for our license.

What other advice do I have?

I would give Cortex XDR a rating of eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros sharing their opinions.