We mainly use it for endpoint protection, exploit prevention, and malware prevention.
Consultant at a tech services company with 501-1,000 employees
User friendly, stable, and automatically correlates events and logs
Pros and Cons
- "It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature. It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else."
- "It is not a suitable solution if you are looking for a single product with multiple features such as DLP, encryption, rollback, etc."
What is our primary use case?
What is most valuable?
It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature.
It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else.
What needs improvement?
It is not a suitable solution if you are looking for a single product with multiple features such as DLP, encryption, rollback, etc.
this is good as an endpoint protection to prevent malware, exploits, zero days, ransomware, botnet etc. For features like Host DLP or encryption or patch management, or any such features which are available in basic anti-virus, you cannot expect it in Palo Alto Network's Cortex XDR solution. rest, all features work as expected, without any lagg or slowness observed in the system.
For how long have I used the solution?
I have been using this solution for a year or something like that. We have been using it from the day they launched or released version 4.0. Currently, they are on version 7.
Buyer's Guide
Cortex XDR by Palo Alto Networks
September 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,759 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable. I have never faced any kind of issues or never heard from any of my colleagues that they have faced any kind of issue.
What do I think about the scalability of the solution?
There is no problem with scalability. Currently, we have around 150 users. In our company, it is compulsory to install this agent on all systems. If we want to scale it, we just need to install an agent. There is no upgrading the server or the hardware because it is a SaaS service provided by Palo Alto Networks.
How are customer service and support?
We directly raise issues with Palo Alto Networks, and they support us. I've never directly created a support query because our IT team looks into support queries, but I think it's pretty easy. You'll never face any kind of issues or challenges in raising support queries.
How was the initial setup?
It was straightforward. In earlier versions, such as version 4.0, it was a bit difficult to install the server and then upgrade the agents and servers. These processes were difficult. There are no complications now.
It took us more than a week to deploy because we were implementing it on the systems of various users who were working from home.
What about the implementation team?
We are a partner of Palo Alto Networks, so we have deployed it directly.
Which other solutions did I evaluate?
We evaluated multiple products. We have evaluated Trend Micro, McAfee, Broadcom Symantec, Sophos, and many other products. Each product is good in its own field. We chose Cortex because we already had a Palo Alto Networks firewall. It got integrated easily, and the co-relation part and the co-relation engine worked very well.
What other advice do I have?
If you are looking for security, mainly for advanced threat prevention from ransomware and malware attacks, I would recommend Cortex. Even if you want to integrate your firewall, I would recommend Cortex, but if you are looking for a single product with multiple options or features, such as DLP, encryption, rollback, and other features, I would not recommend Cortex.
I would rate Cortex XDR a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Network Designer at a computer software company with 1,001-5,000 employees
Easy to set up with excellent trend analytics and isolation feature
Pros and Cons
- "The initial setup is pretty easy."
- "In reporting they should have a customizable dashboard due to the fact that C-level people don't like reporting to the IT department. They prefer to have a real-time dashboard. That kind of dashboard needs to have various customizations."
What is our primary use case?
We primarily use the product as endpoint security which we have deployed on all servers and locations. This is not limited to the endpoint, however, as it has further integration with the firewalls and email solutions. Therefore, it can give us quick visibility in case there is any malicious or suspicious activity happening.
What is most valuable?
The solution offers a very high-performance.
The solution has analytics that watch patterns and trends. If there is a change in user behavior or communication, it has the ability to track that.
The solution has a very helpful isolation feature. If any system gets compromised, with one click I can access the system and isolate it from other networks, and then go into further forensic investigation of the current threat without compromising anything else.
There are a lot of lead solutions in this space, however, Palo Alto is number one.
The initial setup is pretty easy.
What needs improvement?
The solution should enhance the ADR and reporting. As of right now, they are giving reports, which are okay, however, there are other ways to get better reporting. That is an area where I already requested that Palo Alto work on.
In reporting they should have a customizable dashboard due to the fact that C-level people don't like reporting to the IT department. They prefer to have a real-time dashboard. That kind of dashboard needs to have various customizations.
They should extend the solution for URL filtering, as other endpoint security products are doing that already. Nowadays, users are working from home and therefore we have plenty of traffic back through the data center just for URL filtering security. If that functionality could be there in the endpoint, then we would be happy. It would ensure users working from home couldn't access malicious websites.
For how long have I used the solution?
We've been using the solution for one year. Before that, we were using Palo Alto Trap.
What do I think about the stability of the solution?
The solution is very stable. I pretty much depend on product stability. Over the last six months, we have been able to see it's that Palo Alto is more stable than most. There is no such issue in that regard.
This is a very stable product, whether it is running on a database or email system or on any platform. It works perfectly fine.
What do I think about the scalability of the solution?
The solution is very scalable. This is due to the fact that it is being managed through the cloud making it easy to deploy to a thousand endpoints. There is no issue at all. As long as there's enough space for the solution to expand, it can grow out to any size you need.
How are customer service and technical support?
Technical support from Palo Alto is perfect. However, we have first-level support from a third-party. They sometimes take time to respond, which is not ideal. That said, when we get aligned with the tech support from Palo Alto, that really works well. Their level one support is with other vendors, and level two and level three support is with Palo Alto. That's how they are set up. They deal with bigger issues.
Overall, we've been pretty satisfied with technical support.
Which solution did I use previously and why did I switch?
We're service providers. We offer a variety of solutions to our clients, including Palo Alto, Cisco, Microsoft, and McAfee, depending on their needs. We don't just use or recommend one particular endpoint protection product.
About a year back I implemented Cisco and Palo Alto for our customer. Cisco AMP is also a good solution while it is running with the grid, however, I have not been involved with using it for three years.
In routing and switching, Cisco is good. However, Cisco AMP, which is an endpoint security, requires you to work with many other AMP solutions from Cisco.
My first preference would be Palo Alto and my second preference would be Cisco AMP.
How was the initial setup?
The initial setup is not complex at all. It is very straightforward and very easy to implement. I implemented it for 1000 or so users, and it took only about one month to execute. Even when we were in a pandemic situation where users were at home, we did it that quickly. It is very easy to deploy.
What's my experience with pricing, setup cost, and licensing?
The pricing is actually very reasonable. Palo Alto is very invested in some commercial endeavors and they have simplified their license. A team license can be used on-cloud, or on-prem. We have not faced segregation on any technologies, so a simple license gets any user anywhere without limitations. It is easy to increase the license as it's a cloud service. You just speak to your account manager and they can increase the licenses for you.
What other advice do I have?
While we deal with the cloud deployment model, we've also often used the on-premises deployment.
I'd advise other companies to use the solution. It really is the best one out there.
Overall, I'd rate the solution nine out of ten. The reporting is a bit weak, and it's my understanding they are working on that. However, performance-wise and security-wise, this is the best product.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cortex XDR by Palo Alto Networks
September 2025

Learn what your peers think about Cortex XDR by Palo Alto Networks. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,759 professionals have used our research since 2012.
Assistant Superintendent with 51-200 employees
Straightforward to set up and the support is highly-rated
Pros and Cons
- "The interface is easy to use and it is more up to date than our previous solution."
- "Although I would say this product is highly-rated, it could probably do more because nothing does everything that you want."
What is our primary use case?
This product is part of a package that makes up our security solution.
What is most valuable?
The interface is easy to use and it is more up to date than our previous solution.
What needs improvement?
Although I would say this product is highly-rated, it could probably do more because nothing does everything that you want.
For how long have I used the solution?
We have been using this product for about four months.
What do I think about the scalability of the solution?
We think that this product will help us grow. We think that it meets our needs currently, and we can grow with it over time. There 12 people in the IT department who currently manage it.
How are customer service and technical support?
The support is excellent. We had a couple of issues that we had to call for and I would say that they are highly rated.
Which solution did I use previously and why did I switch?
Our older solution was from Fortinet. It was out of date and more difficult to use. The IT staff say that the Palo Alto product is better.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
We worked with a reseller. They came in, we told them what we wanted to do and they set it up to our spec. The person who came in and helped support us was highly skilled and it worked seamlessly.
What's my experience with pricing, setup cost, and licensing?
We pay about $50,000 USD per year for a bundle that includes Cortex XDR.
Which other solutions did I evaluate?
We evaluated Palo Alto and Trend Micro, and we opted for the Palo Alto Cortex XDR.
What other advice do I have?
I don't use this product on a daily basis but we like what we have so far and I would definitely recommend it to other users.
My advice is to make sure that you have a good implementor and that the reseller you're purchasing from gives you a highly-qualified engineer.
Overall, we are happy with this product but that said, nothing does everything that you want.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
This is a recommended solution for total end-to-end protection
Pros and Cons
- "Being a cloud solution it is very flexible in serving internal and external connections and a broad range of devices."
- "The connection to the internet has not performed as expected."
What is our primary use case?
We are still in the testing stages so there is not currently any primary use case beyond the base use of endpoint protection.
What is most valuable?
Cortex has several good features that I am interested in. There is a nice Sandbox function that is very strong, there is the Traps (endpoint protection) solution, the real-time filtering of suspect linkages is good, and the automatic blocking of suspect behavior is always active and protecting the network.
What needs improvement?
As an improvement, I would like to see enhanced connection speeds. On China's side, we need to set up a local server for the definition updates, and the performance has not been very good for the company when directly connected to the internet. We are a little disappointed with that.
For how long have I used the solution?
We have been using Cortex XDR (Extended Detection and Response) for around two months.
What do I think about the stability of the solution?
It is stable. From the moment we installed it has been up with no restarts of maintenance until now.
What do I think about the scalability of the solution?
I think that this product is scalable. The testing environment we use right now has around 200 users. In the future, when we deploy it to the company we will move up to around 4,000 users.
How are customer service and technical support?
The technical support is okay. They have already helped us to fix the installation and then we had an issue and they were available for correction of the problem. They also have made some useful suggestions. So the support team is okay in my estimation.
Which solution did I use previously and why did I switch?
We have been exploring a similar solution. Right now I am also doing testing on Sentinel at the center. This is a similar solution. But we have only just begun testing Sentinel, so we do not really have enough experience with it to comment on the product.
How was the initial setup?
As we just started with Cortex and we are using a cloud solution, I do not have the impression that it was difficult to install and begin using.
What's my experience with pricing, setup cost, and licensing?
The setup costs are a bit higher than some other solutions. Overall it is a little bit expensive, I think. If we could get it for around a 10% discount then that would be a better price point for us.
For our pricing plan, we are not on a subscription, so we do not have to pay every month. We have a yearly license for the product.
The approximate amount we pay per license is around $80 per user per year.
What other advice do I have?
My suggestion for people considering this product is that Cortex is a very good total solution on the endpoints. Because I needed Cortex to work for external and internal users and devices, it helps that it is cloud-based because it is good for working in the office or other locations. So we wanted to have the total end-to-end protection including on the mobile devices, that is what we got. This product will be a good suggestion for people who need the same capability.
On a scale from one to ten where one is the worst and ten is the best, I would rate Cortex XDR as around nine-out-of-ten. The cost is the reason it would not be higher. Nine is good but this is a very good product except for the cost.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Manager at a hospitality company with 10,001+ employees
You can see the value for your money and sleep peacefully at night, not worrying about ransomware attacks
Pros and Cons
- "After deploying Traps, we saw the performance of the network improve by 65 to 70 percent."
- "Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about."
- "There are some default policies which sometimes affect our applications and cause them to run around. In the hotel industry, we use a different type of data versus Oracle and SQL. By default, there are some policies which stop us from running properly. Because of this, the support level is also not that strong. We have to wait to get a results."
What is our primary use case?
I used the product at my previous company until November 2018.
How has it helped my organization?
After deploying Traps, we saw the performance of the network improve by 65 to 70 percent. There was a drop in the latency rate over the application, when accessed via our users. We received feedback from users that usually when they were downloading a bunch of things or browsing the Internet, ad popups would spring up which are a gateway to bring viruses and stick in temp files. This improved a lot because Traps occasionally gives an alert to them to be careful, such as don't go on play on this site and download malicious things. The overall performance of the entire organization was improved because of this.
When I was monitoring Traps, during the period after we deployed it fully on our organization, there was around 125 users on it. We could see in a whole day that there was around 10 to 15 threats which kept popping up. Because I work in the hotel industry, we have a lot of emails which come through worldwide. They are for reservations and booking. Out of those 50 emails, five to six emails are malicious emails which have the extension of .exe files or other encrypted files. They could have had macros enabled in those files as well. Traps would alert us to these malicious files.
The network was infected when we were using Traps. One of the reservation computer was infected with ransomware. It was detected by the Traps. In Traps, it shows up that they investigated the file which was in a zip format. We uncompressed it to view the file and saw Traps detected this infection. It does analysis of all the files to an in-depth level, which was helpful for us to detect and avoid that infection being spread around.
What is most valuable?
A majority of its features are very good, well-designed, and programmed. Most of the machine learning has features where we took a deep analysis on kernel level scanning. It has shown that if in case of anything happens, like first-level operation fails or it went to the next level that it will protect the machine. You can see the artificial intelligence working on it.
What needs improvement?
There are some default policies which sometimes affect our applications and cause them to run around. In the hotel industry, we use a different type of data versus Oracle and SQL. By default, there are some policies which stop us from running properly. Because of this, the support level is also not that strong. We have to wait to get a results.
Originally, we wanted to uninstall Traps because we could not run our operations because Traps, by default, had blocked applications and files. This is still a thing, as we still have to give flexibility to certain policies which are pre-defined in the Traps application.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about.
When the product was updated, I also worked on the latest version.
What do I think about the scalability of the solution?
It is scalable.
We had 150 end users. The end users ranged from the manager level to the supervisor level. These users include salespeople who carry their laptops when travel out of the country on business trips.
How are customer service and technical support?
In this region, I find there are not many good engineers available for Traps. The one guy who specializes in the work functionality, if any issue comes up, might not be available in the country. Therefore, it's a challenging to get the specialized person who knows how to troubleshoot and get the fix. Otherwise, we have to wait for at least 24 hours to get support and results. If an issue comes up because of a new version which we deployed and updated has any changes, we need support immediately, not in 24 hours. For example, we don't know what changes were made to which parameters, what we need to disable or activate, and if they blocked any of the applications, then our operation will get stuck.
Which solution did I use previously and why did I switch?
We were the victim of ransomware. Prior to that we were using an antivirus application from Sophos, which was not able to detect that ransomware engine which encrypted our servers and client machine. So, it was a disaster, and we started looking for another solution which could perform better and give us zero-day threat alerts. I researched which would be the better solution and came across Traps. We ran version 3.5 for a period of one month, where we tested it against malware, viruses, etc. The performance of the Traps has proven itself to work very well in detection.
How was the initial setup?
The initial setup is very straightforward.
The deployment took five minutes to be fully functional and configured. It was just one simple utility which we had to install on the computers. It was not a complex thing once we had it installed. We created a whitelist policy for whatever applications were there. This was a one-time job to streamline the access levels to be allowed. Once the one-time job was done, it gets pushed out to the entire organization.
During the PoC stage, we discussed with the engineer how we wanted it because we had an Active Directory and all the user accounts were connected to the directory. We deployed the data from Traps onto one of the server, then data to the Active Directory. From there, we pushed all the agents to all the users, then we took the file and deployed it. Whenever the users login, it gets deployed and installed. The deployment went very well and was properly executed.
What about the implementation team?
The deployment was done by two engineer from Palo Alto and me. They assured me by installing in two to three machines. There were very simple steps to follow, like three to four steps, for the installation. Afterwards, they took care of deploying Traps for all the users.
The admin has been responsible for maintaining it.
What was our ROI?
The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase.
What's my experience with pricing, setup cost, and licensing?
It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses.
Which other solutions did I evaluate?
I have worked with different product lines: McAfee, ESET Endpoint Security, and Sophos. However, I find the Traps to be much better in comparison to all the other competitors available in the market.
I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require.
What other advice do I have?
Overall, Traps is a very good application when you compare endpoint security solutions available in the market. You can see your value for your money. You can see the results and sleep peacefully. You don't have to worry about a ransomware attack. Traps is very well-designed. It also does good things with deep machine learning. If it finds any malicious activity, it will alert you.
Based on our feedback and recommendations, our sister companies had been looking forward to replacing their current solution with the Traps.
My current company is in the process of evaluating the solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of InfoSec at Jo-Ann Stores
We have not had any malware successfully execute on an endpoint since deploying Traps.
Pros and Cons
- "Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
- "There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration."
What is our primary use case?
Advanced endpoint protection.
How has it helped my organization?
Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place. We have not had any malware successfully execute on an endpoint since deploying Traps.
What is most valuable?
Wildfire, advanced detection capabilities, and whitelist/blacklist features. These features have provided us an easy way to lock down our systems to prevent execution of unknown code and scripts and to prevent launching of code from end user writable directories.
What needs improvement?
The application whitelisting/blacklisting feature is based purely on path and filenames. Changing a filename can bypass it easily. The uninstall admin password for the client is passed in clear text during install.
There is a severe gap in functionality between Windows, Linux, and Mac versions. For example all folder restriction settings are Windows only. Traps 5.0+ does not have SAML / LDAP integration. This is ridiculous for an enterprise product.
Traps 5.0 does not integrate with Palo Alto's Panorama product, which was a big selling point of Traps 4.0. Traps 5.0 has no ability to send an email to alert of detections. Instead customers have to jump through hoops to use Palo Alto's log management service to forward logs into a 3rd party SIEM and then build your alerts from there. No EDR functionality, though this is supposedly coming.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Mostly positive. We've had some episodes early on where upgrades caused some issues with the backend database, but that seems to have cleared up. This issue would not impact the Traps 5.0 users as it is SaaS based.
What do I think about the scalability of the solution?
This software exists on every workstation and server in our company with ~10,000 people using the solution. For on-prem, we run 3 nodes and it handles the load just fine. We could always add more nodes if necessary. For the SaaS solution, that is all on Palo Alto's side.
How was the initial setup?
Setup was pretty straight forward. The product is very granular and customers can turn on features as they are ready/comfortable in order to keep the deployment simple. For organizations with a good understanding of their infrastructure, deployment should be pretty simple.
What about the implementation team?
We deployed Traps ourselves. We went big bang and deployed all features at once. We had a strong understanding of our systems and were able to provide whitelisting settings up front that made sense. There was a bit of post-deployment work to resolve things that were missed, but all things considered the deployment strategy went smoothly and was the right call.
What was our ROI?
For an endpoint security service, that is hard to state. We have not seen a malware infection since deployment.
What's my experience with pricing, setup cost, and licensing?
I feel it is fairly priced.
Which other solutions did I evaluate?
We evaluated
- Palo Alto Networks Traps vs Carbon Black
- Palo Alto Networks Traps vs Cylance
- Palo Alto Networks Traps vs CrowdStrike
- and Palo Alto Networks Traps vs Sophos X.
What other advice do I have?
I think Traps has the best mix of features by price in the industry. It is not flawless by any means, but Palo Alto seems committed to it and are improving it. Traps 5.0 is promising, though they have a ways to go before I'd be willing to implement it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
A stable and scalable solution with good customer support
Pros and Cons
- "The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
- "The product's pricing could be better."
What is our primary use case?
We use the solution for telemetry and for its anti-virus capability.
What is most valuable?
The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better.
What needs improvement?
The product's pricing could be better.
For how long have I used the solution?
I have been using the tool for several years.
What do I think about the stability of the solution?
The solution is stable. I would rate its stability a nine out of ten.
What do I think about the scalability of the solution?
The product is scalable.
How are customer service and support?
The technical support team is good.
How was the initial setup?
The initial setup was easy.
What was our ROI?
The tool is worth its money.
What other advice do I have?
I would rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Project Manager at a outsourcing company with 1,001-5,000 employees
A stable part of our security solution that correlates logs from relevant sources
Pros and Cons
- "The most valuable for us is the correlation feature."
- "There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
What is our primary use case?
We use Cortex XDR as part of our security solution.
How has it helped my organization?
its a very good solution and single solution for entire infrastructure, give us good co-relation of incident. Single solution for Network, Endpoint, Servers.
What is most valuable?
The most valuable for us is the correlation feature. You are able to correlate data that is coming from the firewall, network, server, and endpoints. This is one of our main requirements and makes for a good product.
It works with the data lake in an agent-based or agentless manner.
It is easy to integrate most with network devices, including firewalls, and Active Directory. We use firewalls from different vendors including Palo Alto and Check Point, and it supports them.
What needs improvement?
There are some third-party solutions that are difficult to integrate with, which is something that can be improved.
What do I think about the stability of the solution?
We have not experienced any issues with respect to stability at this point.
What do I think about the scalability of the solution?
Scalability has not been a problem.
How are customer service and support?
We have been in contact with technical support and are satisfied with them.
How would you rate customer service and support?
Positive
How was the initial setup?
its a Straightforward
What about the implementation team?
We have an in-house team for deployment and maintenance.
What was our ROI?
It replace multiple solution and due to this it will reduce the Administrative effort.
Which other solutions did I evaluate?
I have run a PoC with both CrowdStrike and Cortex XDR, and from my observation, I felt that Cortex was much better at meeting our requirements. It is also easier to use.
CrowdStrike was difficult when it came to integrating with other products and it does not work on mobile devices.
What other advice do I have?
My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features. From my experience, it is one of the better ones in the market. That said, no product is 100%.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Extended Detection and Response (XDR) Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) Ransomware Protection AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
Microsoft Defender XDR
HP Wolf Security
Fortinet FortiClient
Elastic Security
WatchGuard Firebox
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Cortex XDR by Palo Alto Networks Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which SIEM is best fit with Palo Alto Cortex XDR?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- Cortex XDR by Palo Alto vs. Sentinel One
- FortiXDR vs Cortex Pro - which is the best?
- Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
- How is Cortex XDR compared with Microsoft Defender?
- Which is better - Cortex XDR or Symantec End-User Endpoint Security?
- How would you compare BlackBerry Protect vs Cortex XDR by Palo Alto Networks?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?