---
title: Cortex XDR Reviews
meta_title: 'Cortex XDR Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 71 reviews by the users' company size, role or industry to
  find out how Cortex XDR works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 71
  scale: '5'
date_modified: '2026-07-26'
parent_category:
  name: Cloud Security
  url: https://www.g2.com/categories/cloud-security
---

# Cortex XDR Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Extended Detection and Response (XDR) Platforms](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 71
## About Cortex XDR
Cortex XDR is the industry’s first extended detection and response platform that stops modern attacks by integrating data from any source. With Cortex XDR, you can harness the power of AI, analytics and rich data to detect stealthy threats. Your SOC team can cut through the noise and focus on what matters most with intelligent alert grouping and incident scoring. Cross-data insights accelerate investigations, so you can streamline incident response and recovery. Cortex XDR delivers peace of mind with best-in-class endpoint protection that achieved the highest combined protection and detection scores in the MITRE ATT&amp;CK® round 3 evaluation. The Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic protection to secure what’s next.



## Cortex XDR Pros & Cons
**What users like:**

- Users value the **important alert notifications** from Cortex XDR, which enhance security without overwhelming them. (2 reviews)
- Users appreciate the **simplicity and manageability** of Cortex XDR, finding it easy to navigate and utilize effectively. (2 reviews)
- Users love the **unique features** of Cortex XDR, especially its effective threat detection without compromising system speed. (2 reviews)
- Users praise the **unified detection and response capability** of Cortex XDR, enhancing threat investigation efficiency and accuracy. (2 reviews)
- Users value the **unified detection and response capability** of Cortex XDR for swift and precise threat investigations. (2 reviews)
- AI (1 reviews)
- AI Technology (1 reviews)
- Alerting (1 reviews)
- Alerts (1 reviews)
- Users appreciate the **effective antivirus protection** of Cortex XDR, as it quickly detects and handles various threats. (1 reviews)

**What users dislike:**

- Users find **limited features** in Cortex XDR, with restrictions affecting core OS functionalities and usability issues on lower-end systems. (2 reviews)
- Users experience a **noticeable performance impact** on lower-end systems with the Cortex XDR agent installed. (1 reviews)
- Users face **compatibility issues** with Cortex XDR, restricting core functionalities and software installations on their machines. (1 reviews)
- Users find the **system complexity** challenging, often struggling with management and a steep learning curve. (1 reviews)
- Users find the **complex management** of Cortex XDR challenging due to its steep learning curve and customization difficulties. (1 reviews)
- Users find the **difficult learning curve** challenging, especially when managing policies and customizing detections in Cortex XDR. (1 reviews)
- Users find the Cortex XDR to be **expensive** for public school systems, but value its worth despite the cost. (1 reviews)
- Users note the **restrictive core functionalities** of Cortex XDR, limiting certain installations and affecting usability. (1 reviews)
- High Resource Usage (1 reviews)
- Users face **installation difficulties** with Cortex XDR, as it restricts some core OS functionalities during setup. (1 reviews)

## Cortex XDR Reviews
  ### 1. Streamlined Threat Detection with Some Setup Challenges

**Rating:** 4.5/5.0 stars

**Reviewed by:** Rohit B. | Assistant Manager - Endpoint Security, Insurance, Enterprise (> 1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I like Cortex XDR for its noise reduction and automation, which saves time for the analysts. Its scalability and simplicity stand out to me. The faster root cause analysis with Cortex XDR improves the efficiency of our analysts and helps in simplifying operations. I also appreciate the readiness it provides.

**What do you dislike about Cortex XDR?**

The initial setup of Cortex XDR was quite complex for me, especially since the rollout was tedious and the policy tuning was very difficult due to our large environment. I found that training is often needed when new features are introduced, which can be challenging to keep up with. Additionally, I've faced integration challenges with third-party tools. The costs can also be an issue, and negotiating the bundle or selectively deploying add-ons is necessary to manage them effectively.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to reduce alert noise and improve endpoint protection. It addresses issues like fragmented visibility and slow response, enhancing analyst efficiency and simplifying operations through automation and scalability, leading to faster root cause analysis and improved readiness.

  ### 2. Causality Engine Delivers Fast, End-to-End Attack Visibility

**Rating:** 4.0/5.0 stars

**Reviewed by:** Amaan M. | Soc Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The endpoint agent and the causality engine really stand out for us. We came from a traditional EDR that generated a flood of separate alerts, so XDR’s ability to tie process, network, and user activity together into a single causal chain has been a big improvement. It lets analysts see the full story of an attack instead of piecing together fragments. Root-cause analysis that used to take an hour of pivoting now takes just minutes.

**What do you dislike about Cortex XDR?**

The management console has a steep learning curve. There are many nested menus, and finding specific settings or policies isn’t always intuitive. New analysts need real ramp-up time before they can be productive in the UI. Some workflows also require jumping between different sections of the console more than they should, which slows things down. Reporting is another weak spot. The built-in reports cover the basics, but anything customized for executive or compliance audiences typically means exporting data and building it elsewhere.

**What problems is Cortex XDR solving and how is that benefiting you?**

The biggest value XDR brings is unified visibility across endpoints, networks, and identities, which eliminates fragmented alerts and the need for manual correlation. Its causality engine automatically links related events into a single incident, giving analysts a clear view of the full attack chain rather than a set of isolated alerts. This can significantly reduce investigation time and support faster triage and containment. In parallel, the unified agent brings prevention, EDR, and host controls together in one solution, helping reduce tool sprawl, endpoint overhead, and day-to-day operational complexity. Overall, the result is better analyst efficiency, stronger security operations, and lower management overhead.

  ### 3. Strong Correlation and Investigation Depth for SOC-Scale Threat Hunting

**Rating:** 4.0/5.0 stars

**Reviewed by:** Alessandro D. | Technical Leader, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

Cortex XDR stands out in day-to-day SOC operations for how effectively it correlates endpoint, network, and cloud telemetry into a single investigative view. As a Technical Lead managing a team of five analysts, I find the incident timeline and causality-chain visualization especially valuable for threat hunting and incident response—it significantly reduces the time needed to reconstruct an attack path versus piecing together logs across siloed tools. The behavioral analytics engine is also strong at detecting living-off-the-land techniques and lateral movement that signature-based tools often miss. Integration with the broader Cortex ecosystem (especially XSOAR for orchestration) further helps by enabling automation of repetitive triage steps, which is particularly important when maintaining H24 on-call coverage.

**What do you dislike about Cortex XDR?**

The learning curve to fully master the platform is steeper than with some competing EDR/XDR solutions, especially when it comes to fine-tuning detection rules to cut down on noise without sacrificing coverage. New analysts on the team need meaningful ramp-up time before they’re fully productive. Licensing and add-on module costs can also add up quickly if you want full XDR capability (network, cloud, identity) rather than endpoint-only coverage. Occasionally, the alert-correlation logic feels opaque, which makes it harder to explain in post-incident reporting why certain events were grouped together.

**What problems is Cortex XDR solving and how is that benefiting you?**

It’s a core part of our detection and response stack, helping us reduce mean time to detect and respond to incidents by consolidating multiple data sources that analysts would otherwise have to hunt through manually. It’s especially useful for correlating phishing-driven incidents with subsequent endpoint activity, and it also supports our escalation workflows during the 24/7 on-call rotation.

  ### 4. Cortex XDR: High-Quality Threat Detection and Fast, Centralized Investigations

**Rating:** 5.0/5.0 stars

**Reviewed by:** A K M Abdullah A. | Founder &amp; Chief Visionary Officer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 17, 2026

**What do you like best about Cortex XDR?**

High-quality threat detection: It uses behavioral analytics and AI to identify malware, ransomware, and other advanced threats beyond traditional signature-based antivirus. Reduced alert fatigue: It groups related alerts into incidents, which helps security analysts focus on the most important threats instead of reviewing hundreds of isolated events. Fast investigation: It provides detailed process trees, timelines, and correlated evidence so analysts can quickly understand how an attack unfolded. Centralized visibility: It offers a single console for monitoring endpoints and other security data, making day-to-day operations more efficient. Strong integration with the Palo Alto ecosystem: Organizations already using Palo Alto firewalls or other Cortex products typically get the most value from the platform. Cortex XDR has performed well in situations where rapid threat detection and response are critical. The platform provides strong visibility across endpoints and other security data sources, allowing our team to quickly identify suspicious activity and understand the full scope of an incident. Its alert correlation capabilities help reduce noise by grouping related events into a single incident, which saves valuable investigation time and enables analysts to focus on higher-priority threats.

In day-to-day operations, Cortex XDR has helped streamline security monitoring and incident response workflows. The detailed investigation tools, including process trees and attack timelines, make it easier to determine root causes and assess impact. This has improved our team's efficiency and reduced the time required to contain and remediate potential threats.

While there is a learning curve to fully leverage advanced features and analytics, the overall benefits in threat visibility, detection accuracy, and response speed have made it a valuable part of our security operations. It has been particularly effective in helping us identify unusual behavior, investigate incidents faster, and maintain a stronger security posture across the organization. Cortex XDR has performed well in situations where rapid threat detection and response are critical. The platform provides strong visibility across endpoints and other security data sources, allowing our team to quickly identify suspicious activity and understand the full scope of an incident. Its alert correlation capabilities help reduce noise by grouping related events into a single incident, which saves valuable investigation time and enables analysts to focus on higher-priority threats.

In day-to-day operations, Cortex XDR has helped streamline security monitoring and incident response workflows. The detailed investigation tools, including process trees and attack timelines, make it easier to determine root causes and assess impact. This has improved our team's efficiency and reduced the time required to contain and remediate potential threats.

While there is a learning curve to fully leverage advanced features and analytics, the overall benefits in threat visibility, detection accuracy, and response speed have made it a valuable part of our security operations. It has been particularly effective in helping us identify unusual behavior, investigate incidents faster, and maintain a stronger security posture across the organization.

**What do you dislike about Cortex XDR?**

One thing I don’t like about Cortex XDR is that it can come with a fairly steep learning curve, particularly for new analysts who want to fully take advantage of its advanced investigation and query capabilities. The initial setup and policy tuning can also take considerable time and expertise, especially when trying to optimize detections while keeping false positives to a minimum. On top of that, some organizations may find the licensing structure and advanced feature add-ons a bit complicated to understand and manage.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps us address the challenge of detecting and investigating threats across multiple security layers by giving us centralized visibility into endpoint, network, cloud, and user activity. Rather than manually correlating alerts from different tools, the platform automatically groups related events into incidents, which improves detection accuracy and reduces alert fatigue. As a result, our team can respond to security incidents faster, spend less time on manual investigations, and maintain clearer visibility into potential threats across the environment.

  ### 5. Premium Price and Steep Learning Curve, Despite Strong AI Threat Detection

**Rating:** 2.5/5.0 stars

**Reviewed by:** Brauny N. | Site Reliability Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** July 15, 2026

**What do you like best about Cortex XDR?**

The UI is clean and the single console makes investigations fast, though the sheer number of settings can feel dense at first. Integrations are a strong point, it pulls endpoint, network, and cloud data together and plays well with the rest of the Palo Alto stack plus third-party feeds. Performance is solid, the agent is lightweight and doesn't drag down endpoints, and queries return quick even across large data sets.
Pricing sits on the higher end, but the ROI holds up once you factor in the tools it replaces and the analyst hours saved on triage. Support and onboarding were smooth, the deployment guidance was clear and response times good, though full tuning takes a few weeks. The AI and threat intel is the standout, behavioral analytics and causality analysis surface real threats with low false positives and cut down manual digging.

**What do you dislike about Cortex XDR?**

The price is the main sticking point, it's a premium product and the licensing adds up fast, especially as you scale endpoints or add modules. The learning curve is real too, the console packs a lot in and getting alerts tuned the way you want takes time upfront.
A few other gripes: initial setup and policy configuration can feel heavy, some advanced features are gated behind higher tiers, and the reporting could be more flexible without exporting to build custom views. Occasional agent updates have needed babysitting. None of it is a dealbreaker, but the cost and ramp-up are worth going in aware of.

**What problems is Cortex XDR solving and how is that benefiting you?**

It replaced a patchwork of separate endpoint, network, and detection tools with one platform, so we're no longer pivoting between consoles or trying to correlate alerts by hand. Everything lands in a single incident view.

The big benefit is speed. Causality analysis shows the full attack chain and root cause, so triage that used to take hours now takes minutes. False positives are low, so the team spends time on real threats instead of chasing noise, and consolidating tools has cut both cost and management overhead.

  ### 6. Outstanding Visibility and Threat Detection with Cortex XDR

**Rating:** 5.0/5.0 stars

**Reviewed by:** Daniel Q. | Math Teacher, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 01, 2026

**What do you like best about Cortex XDR?**

After working with Cortex XDR, I can definitely see why it’s considered one of the leading XDR solutions. The visibility, threat detection, and response capabilities are outstanding.

**What do you dislike about Cortex XDR?**

What I dislike about Cortex XDR is that it can feel overly complex for everyday use. There are so many features and settings that it sometimes takes longer than it should to find what I'm looking for. While it's powerful, I don't think the interface is as intuitive as it could be, and some tasks require more clicks and investigation than I'd expect. It feels like a tool built for experienced analysts rather than something that's easy to use right away.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps solve the problem of having security information scattered across different tools. Instead of manually checking multiple alerts and trying to figure out whether they're related, it correlates activity into a single incident. That saves me time, reduces alert fatigue, and helps me investigate threats more efficiently. As a result, I can respond to potential security incidents faster and spend more time focusing on real threats instead of sorting through false positives.

  ### 7. Highly Effective, Intuitive, but Pricey Security Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Abdiel I. | Food Server, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 09, 2026

**What do you like best about Cortex XDR?**

I thought Cortex XDR was a pretty good service. It was very useful and intuitive to use. I found it easy to set up, and it provided good security, giving peace of mind. The AI tools are very good, contributing to its intuitive nature.

**What do you dislike about Cortex XDR?**

I think just, maybe the pricing, is a bit expensive and they may have an option for simpler use and then an option for advanced security usage. So that, someone that's not familiar with the tools can take advantage of the features. The AI tools are very good. So maybe just update that a little bit more so that it's even more intuitive, I would recommend.

**What problems is Cortex XDR solving and how is that benefiting you?**

I recommended Cortex XDR for enhancing front-end security in our startup, providing peace of mind. It's easy to use and very intuitive, making it straightforward even for newcomers.

  ### 8. XDR multidomain with great performance and reliability

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jesús C. | Head of Security Operations, Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

Multidomain correlation of threats, being genuinely useful. XDR correlates network events, identity, email, etc., clearly showing the root cause behind the alert or incident. The product's performance is very good in terms of endpoint, although, it is true, the investment is higher compared to competitors. The support is useful and the AI roadmap they apply is on par with a leader in cybersecurity.

**What do you dislike about Cortex XDR?**

The justification for the investment, as I said, the cost is higher than competitors, making it difficult to justify the cost to invest in the product year after year.

**What problems is Cortex XDR solving and how is that benefiting you?**

Complete control of the endpoint, additional visibility and monitoring, creating a security monitoring service based on the events generated by the console.

  ### 9. Streamlined Security and Enhanced Visibility with Cortex XDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** David Moisés R. | Business Process Consultant, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 01, 2026

**What do you like best about Cortex XDR?**

I really like the visual incident timeline in Cortex XDR. It saves us hours of guesswork, particularly when an automated script triggers an alert. We no longer have to dig through raw log files to piece together what happened, which was a major issue for us before.

**What do you dislike about Cortex XDR?**

The biggest hurdle is the learning curve for custom threat hunting. They could really improve this by adding a visual, drag and drop query builder instead of forcing the user to write raw code from scratch. Also, configuring the security policies took some work.

**What problems is Cortex XDR solving and how is that benefiting you?**

We use Cortex XDR to protect our servers and workstations, improving threat visibility and integration. It addresses alert fatigue and speeds up investigations by reducing guesswork, offering a visual incident timeline that saves us hours by eliminating the need to sift through raw logs.

  ### 10. AI Integrations and Training That Empower Security Operations Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Enterprise (> 1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

AI intergrations, modern tech transformation and retunr on inveastment with great training aspects. Overall it is a platformt that helps security operaitons and fully empowers visibilty over the nextwok.

**What do you dislike about Cortex XDR?**

The only thing I could think of is that unforunatley I have been seeing more vulnerabilties and CVE repoerts from Palo Alto lately which has me a little concnered about teh backdoors. and third-party upstrema down stream attack surface.

**What problems is Cortex XDR solving and how is that benefiting you?**

The gap it is covereing is attck surface management, visibilty, and use of AI to monitor behavioral based tracking of user, devices, and other IoT devices in daily operations. The Ui/UX is a standard feel so it is not too hard to learn. Also the intergrations with APIs intergrations are good as well.

  ### 11. Robust Detection and Seamless Integration, Steep Pricing

**Rating:** 3.5/5.0 stars

**Reviewed by:** Silvia M. | CISO As a Service, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I really like how Cortex XDR not only detects malicious events but also stops them and prevents harm to devices. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches the alerts, which is valuable to me. Additionally, I appreciate that the transition to Cortex XDR wasn't disruptive for end users since it can coexist with other software, making the change smoother.

**What do you dislike about Cortex XDR?**

I find its pricing per licensing a bit of a downside, and sometimes the learning curve to use Cortex XDR can be a challenge.

**What problems is Cortex XDR solving and how is that benefiting you?**

I find Cortex XDR detects and stops malicious events, protecting my devices from harm. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches my alerts.

  ### 12. Fast, Seamless Region Connections with No Noticeable Latency

**Rating:** 4.0/5.0 stars

**Reviewed by:** Joe F. | UNICEF National Internship Program, Enterprise (> 1000 emp.)

**Reviewed Date:** July 17, 2026

**What do you like best about Cortex XDR?**

So far I don't recognize any latency issues even while it was running in the background. Also it can be connected to different regions quite fast and seamless.

**What do you dislike about Cortex XDR?**

Sometimes it can occupy some memory when my computer is running on a lot of ai processes that are resource hungry. Sometimes region switching fail too

**What problems is Cortex XDR solving and how is that benefiting you?**

I feel more secured to use internet or access want websites because cortex xdr save me the trouble from manually checking website security one by one.

  ### 13. XDR’s Smart Alert Grouping and Automation Cut SOC Triage Time

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

The grouping engine is the standout feature. XDR automatically correlates related alerts into unified incidents, so instead of triaging 30 individual alerts you're reviewing 3-4 cases with full context already stitched together — endpoint telemetry, network activity, and identity signals all in one view.

The causality chain visualization makes it straightforward to trace process trees and understand attack flow without manually pivoting between tools. You can see parent-child process relationships, file writes, network connections, and registry changes in a single timeline.

Automation profiles let you define response actions (isolate host, kill process, quarantine file) that trigger automatically on high-confidence detections, which means analysts only handle the cases that genuinely need human judgment. This significantly reduces alert fatigue and manual toil for the SOC — routine malware detections get contained without anyone touching them.

The interface is clean and the query language (XQL) gives you direct access to raw telemetry when you need to dig deeper than the pre-built views offer.

**What do you dislike about Cortex XDR?**

No out of box fleet sweeping feature. Threat intel integration is weak and lacks actionable context. The agentic assistant (Cortex AI) still has rough edges and provides limited practical value during real investigations.

**What problems is Cortex XDR solving and how is that benefiting you?**

Endpoint security and detection — gives the SOC team deep visibility into endpoint behaviour for alert investigation. The built-in SOAR platform (XSOAR integration) streamlines response workflows, reducing mean time to respond and allowing analysts to focus on genuine threats rather than manual triage steps.

  ### 14. Smart Score and Identity Threat Detection Make Prioritizing Threats Easy

**Rating:** 4.5/5.0 stars

**Reviewed by:** yikhong h. | Senior Network Security Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

Smart Score and it can automate incident scoring that helps analysts prioritize the most critical threats first.
Identity Threat Detection and it can correlate user behavior with endpoint activity to spot compromised credentials.

**What do you dislike about Cortex XDR?**

Cortex XDR by Palo Alto Networks is primarily integrated within the Palo Alto ecosystem. As a result, there are significant functionality gaps between the Windows, Linux, and Mac versions. Additionally, the cost of Cortex XDR is comparatively high.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR improves endpoint visibility by providing real-time insight into endpoint activity, including processes, network connections, registry changes, and file operations. This helps support effective threat hunting and forensic investigations, and gives organizations clearer visibility into their overall endpoint security posture.

  ### 15. Automatic correlation and causal chain of Cortex XDR facilitate root cause analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 20, 2026

**What do you like best about Cortex XDR?**

The main advantage of Cortex XDR lies in its ability to automatically aggregate and correlate data from multiple vectors (such as endpoints, network, and identities). The Data Stitching functionality and the presentation of the causal chain significantly simplify root cause analysis, allowing precise identification of the entry vector and the behavior of complex routines, such as Living off the Land attacks.

**What do you dislike about Cortex XDR?**

The main drawbacks do not lie in the detection capability, but rather in the technical complexity of XQL, the financial investment, and the effort required in the initial phase of agent optimization to avoid performance impact or false positives.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR fundamentally resolves the fragmentation of security visibility and the slowness in investigations. Before its adoption, incident analysis required the manual cross-referencing of data between different platforms (EDR, firewalls, identities, and cloud). The tool eliminates this separation through Data Stitching, correlating telemetry into a single incident and significantly reducing alert fatigue. Additionally, it facilitates the identification of the root cause by visually presenting the causal tree of processes and simplifies the detection of evasive threats that use legitimate system tools (Living off the Land).

  ### 16. Powerful Threat Visibility, but a Steep Learning Curve and Tuning Needed

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Banking | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 09, 2026

**What do you like best about Cortex XDR?**

What I like best about Cortex XDR is how it brings data from endpoints, network activity, and other security sources into one place. It makes investigating threats much faster because you can see the full picture instead of jumping between different tools. The automation and AI-driven analytics also help reduce alert fatigue, so I can focus on the incidents that actually matter

**What do you dislike about Cortex XDR?**

What I dislike about Cortex XDR is that it can have a steep learning curve, especially when you're first getting used to the interface and investigation workflows. Some advanced features take time to master, and the amount of data can feel overwhelming. It can also generate noisy alerts if it's not properly tuned, so regular policy and detection adjustments are important

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR benefits me by giving me a single place to monitor and investigate security events. It helps me identify threats faster, reduces the number of false positives I have to deal with, and automates parts of the investigation process. That means I spend less time on repetitive tasks and more time responding to real security incidents

  ### 17. Lightweight agent and a Modern Console with Strong Vendor Support

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** April 02, 2026

**What do you like best about Cortex XDR?**

Real time detection and prevention, lightweight agent as well as agentless solution available, managed through a single modern cloud-based console. Easy integration with data sources such as Amazon S3, Microsoft Teams, Email messaging, Google Cloud, and more. The Cortex XDR console offers fast and clean user interface, and it opens fast and performs very well. Cost may be high depending on the features selected and the number of devices, but in our deployment it was good investment, considering the level of protection we received and the quality of the support from the vendor. The built-in AI intelligence is an added value.

**What do you dislike about Cortex XDR?**

Licensing can be confusing, especially with the cloud protection, and may add cost quickly. New releases and the added new features require constant learning.

**What problems is Cortex XDR solving and how is that benefiting you?**

Replacing traditional anti-virus product in our environment with Cortex XDR improved drastically the level of protection of our systems and the security of our network. Being a very large company, we were able to acquire the XDR Pro licenses for all our endpoints and benefit for the advances behavioral protection, telemetry and reporting. Our SOC team can quickly identify and stop active threats and keep the environment clean.

  ### 18. Cortex XDR Delivers Powerful Endpoint Control and Extended Detection

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The cortex XDR is not a typical EDR solution it has extended detection and response capabilities which gives full control on the endpoints integrated with it. From isolation to shell control all can be done through cortex XDR.

**What do you dislike about Cortex XDR?**

1- The GUI of the cortex XDR solution is not user friendly.
2- The solution is very expensive for small and mid-size organizations.
3- The deployment of the solution is more complex than normal XDR solution.

**What problems is Cortex XDR solving and how is that benefiting you?**

1- It is giving management interface to maintain and manage all of your assets which is integrated with Cortex XDR.
2- The have both the capability of agent and agentless integration for devices which does not support agent installation.
3- The endpoints can be management by shell control from the XDR solution without interrupting user work.

  ### 19. Cortex XDR Delivers Unified Threat Visibility and Faster Incident Response

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sushriya M. | Advisory Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** March 13, 2026

**What do you like best about Cortex XDR?**

Cortex XDR helps solve the problem of detecting and responding to security threats across endpoints, network and cloud in one platform. It benefits me by giving better visibility into attacks and helping investigate and respond to incidents faster with fewer alerts to analyze. Integration with SIEM solutions is effective. Easy to use on a daily basis. Customer support is effective.

**What do you dislike about Cortex XDR?**

It can be expensive and some advanced features require additional configuration or licensing to use fully.

**What problems is Cortex XDR solving and how is that benefiting you?**

The grouping of alerts and the ability to provide a detailed yet concise overview of each alert including implementation, artifacts, impacts, and the timeline make it much easier to understand what’s happening.

  ### 20. Centralized Palo Alto Logging That Keeps Everything Easy to Review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ernesto M. | IT Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 07, 2026

**What do you like best about Cortex XDR?**

It provides a centralized logging system for all of my Palo Alto logs, keeping everything in one place and easier to review.

**What do you dislike about Cortex XDR?**

It requires a license, and some parts can be difficult to learn if you don’t follow the proper guidance. I think this is because Palo Alto has changed names a few times now.

**What problems is Cortex XDR solving and how is that benefiting you?**

It’s helpful to have centralized log ingestion and monitoring in one place.

  ### 21. Advanced Detection and Extended Telemetry

**Rating:** 4.0/5.0 stars

**Reviewed by:** Christian Noel C. | Jefe Regional de Inteligencia de Ciberseguridad | CIC |, Enterprise (> 1000 emp.)

**Reviewed Date:** April 28, 2026

**What do you like best about Cortex XDR?**

I like the analysis and anomaly detection capabilities of Cortex XDR, as it supports my Blue Team in detecting potential cybersecurity incidents on a daily basis. I also highly value the extended telemetry capability that provides us with extensive details of all alerts and the validations that Cortex XDR has already performed on its own.

**What do you dislike about Cortex XDR?**

The control of applications

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to protect endpoints and servers, it is compatible with Ubuntu and Windows legacy operating systems. It helps us with the detection of cybersecurity incidents and its extended telemetry provides us with complete details and automatic validations.

  ### 22. Advanced Analytics and Root-Cause Clarity for Faster Threat Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 18, 2026

**What do you like best about Cortex XDR?**

Advanced analytics and root-cause analysis. It displays the exact chain of events during an attack, points out precisely how a threat entered the network, and uses machine learning to spot abnormal user or device behavior.

**What do you dislike about Cortex XDR?**

High cost and licensing complexity. It costs significantly more than entry-level EDR solutions and often requires additional licenses to access advanced features such as forensics or identity analytics.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR automatically stitches together telemetry from endpoints, network firewalls, cloud workloads, and identity providers, giving us total visibility. As a result, analysts no longer have to manually piece together logs from different consoles just to understand what happened.

  ### 23. Exceptional Threat Detection and Endpoint Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** anshu Y. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 01, 2025

**What do you like best about Cortex XDR?**

Ability to investigate and remediate security incidents. Cortex XDR protects our endpoints against advanced threats like malware, viruses and ransomware. Cortex XDR is a convenient tool for hunting advanced threats. It is a reliable tool that reduces false positives. Support and integrations with native apps and Broker VM are very simple.

**What do you dislike about Cortex XDR?**

Cortex XDR is a well-suited solution for endpoint protection, hence I don't have any limitations to pinpoint.

**What problems is Cortex XDR solving and how is that benefiting you?**

I am happy to say that Cortex XDR uses the power of AI and Machine Learning to speed up security threat detection and response. Again, Cortex XDR provides bird's-eye visibility into our organization's endpoints. Cortex XDR integrates seamlessly with other security tools, thus improving our security posture.

  ### 24. Unified Threat Detection That Accelerates Investigations

**Rating:** 4.5/5.0 stars

**Reviewed by:** Parth S. | Security Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 10, 2025

**What do you like best about Cortex XDR?**

Its unified detection and response capability that correlates endpoint, network, and cloud telemetry for faster, more accurate threat investigation

**What do you dislike about Cortex XDR?**

Sometimes it feels a bit heavy to manage, and the learning curve can be steeper than expected when tuning policies or customizing detections

**What problems is Cortex XDR solving and how is that benefiting you?**

It pulls together alerts from across endpoints and the network to spot threats sooner, making investigations faster and reducing a lot of manual security noise.

  ### 25. Cortex XDR: Threat Detection made simple

**Rating:** 4.0/5.0 stars

**Reviewed by:** Carlos J. | Threat Detection and Response Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** September 24, 2025

**What do you like best about Cortex XDR?**

I like it's ability to dig into the niche areas of cmd and process trees to identify common used TTPs.

**What do you dislike about Cortex XDR?**

Too many false positives, needs fine tuning or alert fatigue will be a big problem.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex is identifying threats in all the systems layers

  ### 26. Excellent detection and minimal false positives of cortex.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nixon L. | Especialista de ciberseguridad, Enterprise (> 1000 emp.)

**Reviewed Date:** September 30, 2025

**What do you like best about Cortex XDR?**

I highlight its broad scope for detecting potential threats.

**What do you dislike about Cortex XDR?**

The customization it offers usually requires a very manual process.

**What problems is Cortex XDR solving and how is that benefiting you?**

It is offering exceptional protection.

  ### 27. Palo alto Cortex XDR review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Χρηστος . | Junior IT Support, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 13, 2024

**What do you like best about Cortex XDR?**

Easy to setup the endopoint to customers and realtime alerting

**What do you dislike about Cortex XDR?**

Somitimes the alerts arent right. For example cortex thinks tha outlook is a malware

**What problems is Cortex XDR solving and how is that benefiting you?**

You can make the XDR as strticed as you want , so you give different permitions for groups and users

  ### 28. Cortex is technically very sound and good product as per cyber security point of view.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Viral B. | Head IT, Pharmaceuticals, Enterprise (> 1000 emp.)

**Reviewed Date:** January 22, 2024

**What do you like best about Cortex XDR?**

Cortex updates about latest defination as per cyber attacks trends. Also knowlege base documents are very good.

**What do you dislike about Cortex XDR?**

Not user friendly. For ease of use person need to work. Customer support is not good.

**What problems is Cortex XDR solving and how is that benefiting you?**

It help us on secure of assets from cyber attack. Really good product for Cyber Security

  ### 29. Best tool that protects your Computer as a whole

**Rating:** 4.0/5.0 stars

**Reviewed by:** Hasan S. | T24 Technical Consultant, Banking, Enterprise (> 1000 emp.)

**Reviewed Date:** July 06, 2023

**What do you like best about Cortex XDR?**

Cortex XDR is a fantastic utility provided by Palo Alto Networks. It has a vibrant interface and is easy to use. It offers unique features like Anti-Exploit protection along with Anti-Malware protection. The best thing about this software is that while it scans the system, it does not reduce the speed of other tasks. It detects different kinds of bugs like trojan horses and other types of viruses quickly and prompts users to act on those tasks. Overall my experience using this program is very good.

**What do you dislike about Cortex XDR?**

This program is excellent in its unique nature and functionality, except for restricting some core functionalities embedded in Operating System. For example, I installed some software, and it did not allow me to install those on my machine.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helped me in many ways, mainly because it saved me many times from dangerous viruses and trojans. It usually scans my computer as soon as I turn on my machine, and it never slows down my laptop's overall speed or performance. It takes minimal resources to perform its job without impacting other programs to do their jobs.

  ### 30. Best threat protection our school system has ever had.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Shawn O. | Systems Support Specialists, Enterprise (> 1000 emp.)

**Reviewed Date:** September 12, 2023

**What do you like best about Cortex XDR?**

The simplicity of the interface and the managability of the platform.

**What do you dislike about Cortex XDR?**

Cost of product is pretty high for a public school system but well worth the price you pay.

**What problems is Cortex XDR solving and how is that benefiting you?**

It has resolved our threat prevention and detection issues.  We use to use a basic AV platform and we tried several but this has been a game changer for us.

  ### 31. An Effective EDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2023

**What do you like best about Cortex XDR?**

This EDR solution stands out as highly effective in the market, excelling at managing and deploying a large number of endpoints seamlessly. Its versatility extends to supporting various operating systems, making it a convenient choice. The user-friendly interface further enhances its appeal, ensuring ease of use.

**What do you dislike about Cortex XDR?**

The frequency of false positives detected can be improved for better accuracy. Additionally, there is room for enhancement in customer service to address and resolve queries more effectively.

**What problems is Cortex XDR solving and how is that benefiting you?**

It improves business process outcomes by streamlining and optimizing various workflows. It fosters internal and operational efficiencies, leading to increased productivity and cost savings. The advanced data analytics and insights provided by the suite, decision-making processes are enhanced, allowing businesses to make more informed and strategic choices.

  ### 32. Amazing solution for endpoint protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ahmed A. | Information Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2023

**What do you like best about Cortex XDR?**

It is user friendly solution and cloud based endpoint protection soft. It is the number one in the sector.

**What do you dislike about Cortex XDR?**

About linux protection I fan say that it should be improved

**What problems is Cortex XDR solving and how is that benefiting you?**

We are protecting our endpoints and manage in some cases

  ### 33. Cortex XDR, The All-In-One Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Primary/Secondary Education | Enterprise (> 1000 emp.)

**Reviewed Date:** June 30, 2022

**What do you like best about Cortex XDR?**

Cortex XDR is highly sophisticated software that's backed by Artificial Intelligence and Machine Learning. I've appreciated how it only pushes alerts that are truly important.

**What do you dislike about Cortex XDR?**

There is a noticeable performance impact on lower-end systems where the Cortex XDR agent is installed. I'd also like the quick launcher to have an option to open the endpoint in the All Endpoints section.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR gives full coverage against all categories of malicious threats. It's been really nice being able to trust Cortex XDR to take care of our endpoints. Cortex XDR is super easy to use compare to TRAPS.

  ### 34. Cortex XDR is a great new solution for endpoint protection

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 22, 2022

**What do you like best about Cortex XDR?**

Cortex has a great interface - easy to navigate, nice design, very functional

**What do you dislike about Cortex XDR?**

It was a tad difficult to figure out where to configure initial setup - but once I located that, was simple

**What problems is Cortex XDR solving and how is that benefiting you?**

New type of antivirus/antimalware detection - simple installation, small footprint, so far I am liking it

  ### 35. Best tool to reduce the work load from Secops

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 01, 2022

**What do you like best about Cortex XDR?**

Overall experience with this product is really good, This tool reduces the load from the SecOps team with the help of incident Detection, Alerts and Analysed report.

**What do you dislike about Cortex XDR?**

Nothing, Working perfectly for our organization

**What problems is Cortex XDR solving and how is that benefiting you?**

The mostly liked the about this tool unified Incident management and its detecting the incidents from the sensors and managing the cross platform detection the incidents.

  ### 36. Works and integrates well with Palo Alto NGFW

**Rating:** 4.5/5.0 stars

**Reviewed by:** Mike P. | Network Services Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 11, 2021

**What do you like best about Cortex XDR?**

Reporting/inventory of systems and being able to identify agent levels and operating system.  The ability to triage/investigate from the mainpage is great.  The continual development is nice as we've seen steady improvement from the Traps days.

**What do you dislike about Cortex XDR?**

licensing has been a bit all over the place and hopefully is simplified now.  Would love to see it integrate more with other security products and not just Palo Alto.  Bringing some extra flexibility would be nice.

**What problems is Cortex XDR solving and how is that benefiting you?**

Being able to identify machines that don't have coverage has always been the problem.  We have increased visibility now that we've never had before.  Ease of deployment and upgrades of agents is also fairly straightforward.

  ### 37. Cortext XDR - Good AV

**Rating:** 4.5/5.0 stars

**Reviewed by:** Ashley M. | System Administrator, Enterprise (> 1000 emp.)

**Reviewed Date:** January 13, 2022

**What do you like best about Cortex XDR?**

Centralised management interface and stability of client

**What do you dislike about Cortex XDR?**

Agent was unstable once or twice on inital update

**What problems is Cortex XDR solving and how is that benefiting you?**

Early protection from virus threats

  ### 38. Cortex XDR best in Endpoint Protection and also provides Wealth of information from Endpoint

**Rating:** 5.0/5.0 stars

**Reviewed by:** Tony I. | Snr Security analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** May 06, 2021

**What do you like best about Cortex XDR?**

Ease of use and details information provided from Endpoints. Cortex XDR also detects threats with behavioral analytics more accurately and allows you to contain and isolate endpoints quickly before any damage is done.

**What do you dislike about Cortex XDR?**

Cortex XDR does not currently allow us to download Policies, thereby making it difficult to audit applied policies Easily.

**What problems is Cortex XDR solving and how is that benefiting you?**

Problem: Ensuring Endpoints are protected using both signature and behavioral pattern
benefit: Tight integration with enforcement points accelerates containment, enabling you to stop attacks before the damage is done.

  ### 39. Best tool to avoid security attacks like DDOS

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 18, 2021

**What do you like best about Cortex XDR?**

speed up the  RCA investivation of unwanted security attacks with analytics
Easy to use
Nominal charges
Offers endpoint management

**What do you dislike about Cortex XDR?**

Nothing to be disliked about this  product

**What problems is Cortex XDR solving and how is that benefiting you?**

Investigating and eliminating security attacks
Endpoint management

  ### 40. Execute network-wide information security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Billy S. | IT Specialist, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 10, 2019

**What do you like best about Cortex XDR?**

It is very helpful to handle the various operational requirements of firewalls with Palo Alto. It allows you to build shared laws which can be enforced in many proxy servers. It also utilizes software actions to spot hostility and prevent our system.  As each category of firewalls has different uses, Palo Alto helps to detect if there are unidentified devices that generate unwanted traffic and what sort of traffic it is. Also, filters introduced between organizational sessions in several areas are able to remain permanent.

**What do you dislike about Cortex XDR?**

It is very helpful to handle the various operational requirements of firewalls with Palo Alto. It allows you to build shared laws which can be enforced in many proxy servers. It also utilizes software actions to spot hostility and prevent our system.  As each category of firewalls has different uses, Palo Alto helps to detect if there are unidentified devices that generate unwanted traffic and what sort of traffic it is. Also, filters introduced between organizational sessions in several areas are able to remain permanent.

**Recommendations to others considering Cortex XDR:**

Palo Alto Panorama is a great option if in your workplace there are specific conditions for various firewall classes. It allows you to track aspects such as scheduling and tools that are accessible. However, the effective tracking system has its flaws, that's why I don't consider it as an all-in solution.

**What problems is Cortex XDR solving and how is that benefiting you?**

We use Palo Alto for unified firewall monitoring and regulation of the execution of network-wide information security. We attempted other AV services, but at some stage they all crashed and Palo Alto Panorama have rarely disappointed us.

  ### 41. Handle all of our settings at all of our distinct locations

**Rating:** 4.5/5.0 stars

**Reviewed by:** Pedro C. | IT Specialist, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 08, 2019

**What do you like best about Cortex XDR?**

Palo Alto Traps is very helpful for updating the majority of the software by a single tap. The Control Panel and the ACC provide helpful data to display all firewalls or to be able to select which one we want to work with.  

**What do you dislike about Cortex XDR?**

We switch from local to the cloud variant of Traps, as in the cloud version's there were almost no training alternatives, which have changed over time.  Also, sometimes the PANOS extension to the firewalls merely stops working with no particular reason. In general, I think the system does not have a big customer environment. Also, it appears to be too severe (so much that’s unnecessary) when any small threat is detected.

**Recommendations to others considering Cortex XDR:**

If a customer wishes to readily handle the configurations, or want to handle firewall backups without running between so many cabinets, Palo Alto Traps is vital and straightforward.  However, you must consider that this tool is not meant to be used as a tool for monitoring your system.

**What problems is Cortex XDR solving and how is that benefiting you?**

Palo Alto Traps is used by our network safety group to handle all of our settings at all of our distinct locations. Only IT staff are responsible for device management of these tools.  It is also used to implement central console patches and press strategies. I think of Palo Alto Traps as a useful method to retain data and to maintain the division of duties separate, as we can offer participants from other groups a little space to display the settings without providing them with immediate entry to the firewalls.

  ### 42. One of the better endpoint security products

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Fund-Raising | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 16, 2019

**What do you like best about Cortex XDR?**

Traps has prevented anomalous behavior in our environment a couple of times. This has saved us a lot of trouble. The management interface is intuitive and easy to comprehend. Agent impact on performance in negligible.

**What do you dislike about Cortex XDR?**

At the moment the rollout on MacOS Cataline gave us a little headache, but as of today Traps supports Cataline. Just make sure you update Traps first to the newest version. Otherwise you have to uninstall Traps and reinstall the new version. 
I don't like to way to create Agent Installations. For every new version you create a new installation "package". You should never delete it as long as machines make use of that installation.Just hide them. But it feels this could be done easier.

**Recommendations to others considering Cortex XDR:**

Definitely try Palo Alto Traps as one of your choices if you are looking for a new product. Especially if you have more Palo Alto products.

**What problems is Cortex XDR solving and how is that benefiting you?**

A legacy signature based antivirus doesn't work nowadays. You need behavior based detection. Traps has this and is a full replacement for a signature based antivirus. As admins we feel a lot more at ease.

  ### 43. Great Next Gen Antivirus

**Rating:** 5.0/5.0 stars

**Reviewed by:** Joe W. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 28, 2018

**What do you like best about Cortex XDR?**

The ability to configure it and know that it will auto update without needing regular input. 

**What do you dislike about Cortex XDR?**

If a piece of software gets updated that you have whitelisted by hash control, it can re trigger after each update. This only happens with smaller oneoff software the system hasnt seen before, 

**Recommendations to others considering Cortex XDR:**

This is a great product and we couldn't be happier with it. If you need something that wont require having someone look at every issue in it and fix issues daily, this is a great fit. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Palo Alto is our primary antivirus and ransomware protection. 

  ### 44. Excellent threat hunting capabilities 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** January 24, 2018

**What do you like best about Cortex XDR?**

that with secdo our security team is really able to be proactive and not just handle alerts in a reactive way. Because we handle alerts faster, we have time to threat hunt – based on leads, IOCs or even behavioral IOCs we created in secdo. 

And because they record all endpoint activity and store it for months – we can really hunt. We can find advanced, fileless, and in-memory attacks, and go deep into suspicious activity to identify anomalies that could lead to silent threats. 


**What do you dislike about Cortex XDR?**

I am waiting for them to add some features we asked for, but other than that - none. 

**What problems is Cortex XDR solving and how is that benefiting you?**

the biggest problem we had is the lack of time and tools to effectively hunt for threats that our detection/protection systems didn’t catch. So with Secdo our tier1 analysts handle most alert WORK, and the Tier 2/3 can actually have time to hunt. and the hunting is really granular and depth – because they store endpoint activity and let you search everything. We actually found hidden threats in our network already a week after we start using Secdo. It’s a really useful tool for sec teams 

  ### 45. EDR with focus on SOC problems, very good 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 28, 2017

**What do you like best about Cortex XDR?**

Most EDR vendors focus on the detection and prevention part. But our security team focuses on the part of collecting endpoint information, investigating alerts, responding to threats and hunt for new ones. Secdo is one of the only vendors who focuses on solving the real problems that SOC teams are facing. We have enough alerts coming in from all of our detection and prevention systems – the problem we have is dealing with them  - and SECDO is very good at that. I really recommend

**What do you dislike about Cortex XDR?**

It’s not that I dislike, but Secdo is meant to be used by matured SOC teams. If you are a “one man show” doing security operations – Secdo is probably not for you. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Reducing risk. We don’t miss any alerts so we don’t miss threats, and this reduces the chances of having a breach (which we all know we can’t 100% avoid) become a data breach.  That’s the key benefit for us, so even if an attack has succeeded, we will catch it and respond to it fast enough to make sure it doesn’t have time to actually do any harm in our network. 

  ### 46. Great combination of EDR with security automation

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Small-Business (50 or fewer emp.)

**Reviewed Date:** January 02, 2018

**What do you like best about Cortex XDR?**

We're aware of some of the top EDRs - None of them gives an automation layer that would allow insight to investigate incidents and alerts automatically.
That’s a game changer for us – instead of drilling into each alert and trying to match it with the relevant endpoint data – Secdo does that automatically for us (they call the algorithm that does that ‘causality analysis engine’).

**What do you dislike about Cortex XDR?**

Orchestration would be a great add on for such a product

**Recommendations to others considering Cortex XDR:**

Definitely get involved with this product - it's ease of use, ability to drill down and coverage at volume would make your life easier !

**What problems is Cortex XDR solving and how is that benefiting you?**

we don't have the capacity to investigates all of our daily alerts.
Secdo allows us to get better coverage, about 30 times the coverage which is unbelievable !

  ### 47. SecDo Host visibility – for IT and Security

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Enterprise (> 1000 emp.)

**Reviewed Date:** January 02, 2018

**What do you like best about Cortex XDR?**

Their endpoint visibility capabilities. From what I’ve seen in other EDR tools, they
have 3 advantages:
 Thread level visibility (all others do process level visibility)
 They keep all endpoint data that they collect for a minimum of 30 days (all
the other vendors keep it up to 30 days)
 They collect way more endpoint activity types then other EDRs, so they also
cover uses cases as insider threats, business risk, user activity, policy
violations, System/File attribute violations, etc.)

**What do you dislike about Cortex XDR?**

That they don’t also have an EPP solution. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Before Secdo, both the IT team and the security team were lacking information
about what’s going on our endpoints. We needed it for IT inventory, compliance, and
risk assessment, and for insider threats. So we searched for EDR tools that have the
most granular endpoint visibility. We tested 5 and decided about Secdo. With Secdo
we can query the endpoint population to identify areas of risk and possible
vulnerabilities (we see into USB activity, installed software, autoruns, downloaded
files, running drivers, and even captures of users’ screens)

  ### 48. ELEKS bolsters its security services by partnering with Secdo

**Rating:** 4.0/5.0 stars

**Reviewed by:** Iurii G. | Head of Corporate Security, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** October 30, 2017

**What do you like best about Cortex XDR?**

I’m pleased to introduce the ELEKS new security service portfolio powered by Secdo. Secdo’s preemptive incident response platform allows slashing the incident response time from months to minutes. We are happy to use this solution in-house as well as to recommend it to our customers. This partnership brings a strong security support to our business and allows us to offer improved security services to our clients.

**What do you dislike about Cortex XDR?**

Often we need some additional functionality (flexible reporting for instance), more visibility into agents and their hardening from the solution itself. Anyway, Secdo team is amazingly professional and we have it within days or already in the product roadmap.

**What problems is Cortex XDR solving and how is that benefiting you?**

- ELEKS quickly and cost-effectively introduced new services – prompt incident response, threat-hunting. 
- We are able to perform remote response without impacting business productivity, remote remediation while end-users continue to work.

  ### 49. Next Gen Anti Virus - Finally ready for the marketr

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Entertainment | Enterprise (> 1000 emp.)

**Reviewed Date:** May 05, 2018

**What do you like best about Cortex XDR?**

We have used traps for 2 years now and the 5.0 platform solves so many of the current issues. The interface is 100x better and the application protects us the way it should.

**What do you dislike about Cortex XDR?**

My only complaint is that you still cant use the traps client as a palo alto identity source for User ID.

**Recommendations to others considering Cortex XDR:**

Take a look at Traps and carbon black. They are both great next gen firewalls.

**What problems is Cortex XDR solving and how is that benefiting you?**

Protection from Malware/Spyware/Ransomware.

  ### 50. Well done product, it's give us eyes where we ware blinds.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Banking | Enterprise (> 1000 emp.)

**Reviewed Date:** September 13, 2017

**What do you like best about Cortex XDR?**

the search is quick, i can't say that we are blinds anymore. the customer service is extraordinary. definitely  great value for the product. ha

**What do you dislike about Cortex XDR?**

Heart beat is not exists in the product, so we are bare for technical issue. 

**Recommendations to others considering Cortex XDR:**

I think that if you really want to understand Secdo, you have to go to one of their conventions, it's clarify many things about the product, and bring visual view of how it's operate.
I didn't experienced with Carbon Black and  know how good the product only by rumors , so I think that there is a head to head fight between those to leaders and in my opinion Secdo are definitely on the right path to become the main leader in Incident Respond market. 

**What problems is Cortex XDR solving and how is that benefiting you?**

I can hardly say that we has business issues, it really looks like that SecDo make lots of effort to make the customers satisfy. 


## Cortex XDR Discussions
  - [What is Cortex XDR?](https://www.g2.com/discussions/what-is-cortex-xdr) - 1 comment

- [View Cortex XDR pricing details and edition comparison](https://www.g2.com/products/palo-alto-networks-cortex-xdr/reviews?section=pricing&secure%5Bexpires_at%5D=2026-07-26+12%3A41%3A42+-0500&secure%5Bsession_id%5D=b7aa5eac-0553-40c2-b16e-2ed3704e6a08&secure%5Btoken%5D=629be4941b8c7ea7ae2f069b6c16c7f89109e2963680ce46bef236c8bbd674a6&format=llm_user)
## Cortex XDR Integrations
  - [Amazon Simple Storage Service (S3)](https://www.g2.com/products/amazon-simple-storage-service-s3/reviews)
  - [Google Cloud Storage](https://www.g2.com/products/google-cloud-storage/reviews)
  - [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  - [Google Workspace](https://www.g2.com/products/google-workspace/reviews)
  - [Graylog](https://www.g2.com/products/graylog/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [RadarQ](https://www.g2.com/products/radarq/reviews)

## Cortex XDR Features
**Administration**
- Compliance
- Web Control
- Application Control
- Asset Management
- Device Control

**Analysis**
- Incident Reporting
- Network Visibility
- Metadata Enrichment
- Metadata Management

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- System Isolation
- Firewall
- Endpoint Intelligence
- Malware Detection

**Response**
- Incident Alerts
- Response Orchestration
- Response Automation

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility

**Security**
- Data Security
- Data loss Prevention
- Security Auditing

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Analysis**
- Automated Remediation
- Incident Reports
- Behavioral Analysis

**Detection**
- Multi-Network Monitoring
- Asset Discovery
- Anomaly Detection

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Identity**
- SSO
- Governance
- User Analytics

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Detection and Response (CDR)**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Services - Network Detection and Response (NDR)**
- Managed Services

**Services - Extended Detection and Response (XDR)**
- Managed Services

**Services - Cloud Detection and Response (CDR) **
- Managed Services

## Top Cortex XDR Alternatives
  - [Sophos Endpoint](https://www.g2.com/products/sophos-endpoint/reviews) - 4.7/5.0 (793 reviews)
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (416 reviews)
  - [ESET PROTECT](https://www.g2.com/products/eset-protect/reviews) - 4.6/5.0 (962 reviews)

