Palo Alto Networks Cortex XSOAR enhances security operations automation and integration. Users rely on its incident management capabilities and machine learning to improve response times and efficiency.


| Product | Mindshare (%) |
|---|---|
| Palo Alto Networks Cortex XSOAR | 8.6% |
| Microsoft Sentinel | 11.2% |
| Splunk SOAR | 7.6% |
| Other | 72.6% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Security Orchestration Automation and Response (SOAR) | Apr 28, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Apr 28, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Microsoft Sentinel | Apr 28, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Splunk SOAR | Apr 28, 2026 | Download |
| Comparison | Palo Alto Networks Cortex XSOAR vs Torq | Apr 28, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| IBM Security QRadar | 4.0 | 5.7% | 90% | 217 interviewsAdd to research |
| Microsoft Sentinel | 4.1 | 11.2% | 93% | 109 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 19 |
| Midsize Enterprise | 6 |
| Large Enterprise | 23 |
| Company Size | Count |
|---|---|
| Small Business | 308 |
| Midsize Enterprise | 168 |
| Large Enterprise | 641 |
Cortex XSOAR stands out for its capability to automate and orchestrate security tasks through customizable playbooks and robust third-party integrations. Its analytics offer insights into incidents, while machine learning prioritizes alerts and reduces false positives. Despite its powerful features, users note room for improvement in documentation, interface design, and integration capabilities. Cost and complexity in setup and deployment are also concerns. Users in security operations centers benefit significantly from automated data enrichment, streamlined incident response, and efficient handling of threats like phishing and endpoint management.
What are the key features of Cortex XSOAR?Cortex XSOAR is implemented across industries for automating and streamlining security operations. Organizations use it to create playbooks, integrate with security tools, and automate repetitive tasks, thereby improving the efficiency of their security operations centers and incident management processes.
Palo Alto Networks Cortex XSOAR was previously known as Demisto Enterprise, Cortex XSOAR, Demisto.
Cellcom Israel, Blue Cross and Blue Shield of Kansas City, esri, Cylance, Flatiron Health, Veeva, ADT Cybersecurity
| Author info | Rating | Review Summary |
|---|---|---|
| Enterprise Security Architect V at FirstEnergy | 4.5 | I find Palo Alto Networks Cortex XSOAR a highly customizable and automatable central hub for incident response, despite occasional system slowdowns with high alert volumes. Setup was easy, and it aids metric tracking, though support has time zone challenges. |
| Lead Application Security Engineer Iv at a financial services firm with 5,001-10,000 employees | 4.5 | I value Cortex XSOAR for its security automation, playbooks, and integrations, dramatically improving SOC efficiency. My main concern is the poor UI/UX, and initial setup challenges, though stability and scalability are generally strong. |
| Vice President, Technology at Cache Digitech Pvt Ltd. | 3.0 | As a reseller, I find Palo Alto Networks Cortex XSOAR offers good automation, analytics, and integrations, with great support. However, its high cost limits it to larger companies, and it needs more low-code features. I rate it 6/10. |
| Assistant Security Architect at Cloudnomics | 4.0 | I use Cortex XSOAR for malware incidents, valuing its automation and marketplace for reducing MTTR. Yet, I find playbook creation difficult for junior analysts, despite the product's stability, scalability, and easy integration. |
| Manager at Deloitte | 4.5 | I find XSOAR excellent for automation, compliance, and multi-language scripting, making orchestration easy. Its heavy UI and high licensing costs are major drawbacks, but it delivers significant ROI for mature SOCs. |
| Presale Engineer at Westcon-Comstor | 4.0 | I use Cortex XSOAR as a stable and scalable orchestration automation platform for security events, rating it 8/10. While its versatility and automation are valuable, its complexity and integration requirements mean deployment isn't easy. |
| Cyber Security Analyst at Altisec Technologies Pvt Ltd | 5.0 | I find Cortex XSOAR excellent for streamlining security and automating complex playbooks. Its vast integration library and scalability are valuable, though Python playbook creation can be tedious. I've experienced great stability and support, rating it 10/10. |
| Delivery Manager at a tech services company with 1,001-5,000 employees | 4.5 | I find Cortex XSOAR essential for large, stable security operations due to its automation and comprehensive features. However, its high cost and large scale make me wish Palo Alto offered a lighter, more accessible version for smaller organizations. |