• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Cortex XDR
Logo of Cortex XDR

Cortex XDR

byPalo Alto Networks
in
4.6
2025
Market Presence: Endpoint Protection Platforms (Transitioning to Endpoint Protection), Extended Detection and Response

Overview

Review Summary
AI Generated Using Real User Reviews

See a synthesized overview of the key takeaways from verified reviews of Cortex XDR.

Product Information on Cortex XDR

Updated 13th October 2025

What is Cortex XDR?

Cortex XDR is a software developed by Palo Alto Networks that integrates data from network, endpoint, and cloud sources to detect, investigate, and respond to cyber threats. The software enables security teams to identify suspicious behavior, conduct root cause analysis, and respond to incidents through automated response capabilities. It provides analytics-driven threat prevention and leverages behavioral analytics to correlate alerts across different environments, helping organizations reduce risks from advanced attacks. Cortex XDR addresses challenges of fragmented security data and manual threat investigations by consolidating security operations into a single platform, allowing for more efficient detection and response workflows.

Cortex XDR Pricing

Cortex XDR software utilizes a subscription-based pricing model, where charges are typically determined by factors such as number of endpoints, data ingestion volume, or user count. Pricing varies according to the chosen features, deployment scale, and support options, with additional costs for advanced capabilities and integrations. Licenses are available in different tiers to address varying organizational needs for threat detection and incident response.

Overall experience with Cortex XDR

Sales Manager
<50M USD, Energy and Utilities
FAVORABLE

“Strong and flexible solution with solid real - world performance in production environments.”

4.0
May 14, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.
It Associate
500M - 1B USD, Construction
CRITICAL

“Cortex XDR: a discreet yet effective solution for workstation security”

3.0
Apr 16, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.
Automated Translation from French

Badges

Gartner Peer Insights recognizes vendors who meet or exceed both the market average Overall Experience and the market average User Interest and Adoption score through a Customers’ Choice distinction.
2025
For Market:
Mobile Threat Defense (Transitioning to Workspace Security Platforms)

About Company

Company Description

Updated 7th December 2023

Palo Alto Networks is a global cybersecurity organization shaping the future of cloud-centric technology. The main business objective is to provide effective cybersecurity solutions, maintaining and valuing the digital way of life. It addresses the significant issue of maintaining digital security in an increasingly online-centric world. The company utilizes innovative approaches leveraging advancements in artificial intelligence, analytics, automation, and orchestration. Offering an integrated platform and bolstering a burgeoning ecosystem of collaborators, it assures protection across various platforms including clouds, networks, and mobile devices. The organization envisions a progressively safe and secure digital world each day.

Company Details

Updated 1st July 2025
Company type
Public
Year Founded
2005
Head office location
SANTA CLARA, United States
Number of employees
10001+
Website
http://www.paloaltonetworks.com

Do You Manage Peer Insights at Palo Alto Networks?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top Cortex XDR Alternatives

Logo of CrowdStrike Falcon
1. CrowdStrike Falcon
4.7
(3300 Ratings)
Logo of SentinelOne Singularity Endpoint
2. SentinelOne Singularity Endpoint
4.7
(3106 Ratings)
Logo of Sophos Endpoint
3. Sophos Endpoint
4.8
(2416 Ratings)
View All Alternatives

Peer Discussions

Cortex XDR Reviews and Ratings

4.6

(787 Ratings)

Rating Distribution

5 Star
61%
4 Star
36%
3 Star
3%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?
  • Sales Manager
    <50M USD
    Energy and Utilities
    Review Source

    Strong and flexible solution with solid real - world performance in production environments.

    4.0
    May 14, 2026
    Cortex XDR provides strong endpoint detection and response capabilities with good visibility across incidents and effective threat correlation. The platform works well in enterprise environments and integrates effectively with the broader Palo Alto NEtworks ecosystem. Deployment and policy management are generally straightforward, and customers appreciate the centalized management and analytics capabilities. The main challenges are related to licensing complexity , pricing , and the lerning curve for advanced features and tuning , in some environments , initial configuration and optimization require experienced administrators to fully utilize the platform`s capabilities . Overall , the product delivers solid security outcomes and reliable protection for enterprise customers.
  • Sales Manager
    <50M USD
    Energy and Utilities
    Review Source

    Strong and flexible solution with solid real - world performance in production environments.

    4.0
    May 14, 2026
    Cortex XDR provides strong endpoint detection and response capabilities with good visibility across incidents and effective threat correlation. The platform works well in enterprise environments and integrates effectively with the broader Palo Alto NEtworks ecosystem. Deployment and policy management are generally straightforward, and customers appreciate the centalized management and analytics capabilities. The main challenges are related to licensing complexity , pricing , and the lerning curve for advanced features and tuning , in some environments , initial configuration and optimization require experienced administrators to fully utilize the platform`s capabilities . Overall , the product delivers solid security outcomes and reliable protection for enterprise customers.
  • Read All 848 Reviews

    Get unlimited access to verified peer reviews and insights

    Read unlimited Gartner-vetted product reviews
    View and share valuable product insights
    Download full product profiles
    Review products you use today

Recommended Gartner Insights

  • Critical Capabilities for Endpoint Protection Platforms (Transitioning to Endpoint Protection)
  • Magic Quadrant for Endpoint Protection Platforms (Transitioning to Endpoint Protection)
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

User Sentiment About Cortex XDR
Reviewer Insights for: Cortex XDR
Deciding Factors: Cortex XDR Vs. Market Average
Performance of Cortex XDR Across Market Features

Cortex XDR Likes & Dislikes

Like

What I lie the most: q. advanced threat detection and correlation - it combines endpoint , network , and cloud data to detect complex, multi - stage attacs and reduce false positives through strong analytics and correlation. 2. Automated investigation and response XDR capabilities)- the platform helps secuitty teams quickly investigate incidents with built - in automation, guided workflows, and response actions that reduce manual effort, 3. Centralized management and visibility - it provides a single console for monitoring endpoints and incidents, giving clear visibility across the environment and improving operational efficiency for SOC teams. 4. Strong integration within the PAN ecosystem- works well with other security products from PAN , enabling better thereat intelligence sharing and coordinated defense.

Like

What I lie the most: q. advanced threat detection and correlation - it combines endpoint , network , and cloud data to detect complex, multi - stage attacs and reduce false positives through strong analytics and correlation. 2. Automated investigation and response XDR capabilities)- the platform helps secuitty teams quickly investigate incidents with built - in automation, guided workflows, and response actions that reduce manual effort, 3. Centralized management and visibility - it provides a single console for monitoring endpoints and incidents, giving clear visibility across the environment and improving operational efficiency for SOC teams. 4. Strong integration within the PAN ecosystem- works well with other security products from PAN , enabling better thereat intelligence sharing and coordinated defense.

Like

What I lie the most: q. advanced threat detection and correlation - it combines endpoint , network , and cloud data to detect complex, multi - stage attacs and reduce false positives through strong analytics and correlation. 2. Automated investigation and response XDR capabilities)- the platform helps secuitty teams quickly investigate incidents with built - in automation, guided workflows, and response actions that reduce manual effort, 3. Centralized management and visibility - it provides a single console for monitoring endpoints and incidents, giving clear visibility across the environment and improving operational efficiency for SOC teams. 4. Strong integration within the PAN ecosystem- works well with other security products from PAN , enabling better thereat intelligence sharing and coordinated defense.

Dislike

From the user's (non-administrator's) point of view, no blocking points have been identified.

Automated Translation from French
Dislike

From the user's (non-administrator's) point of view, no blocking points have been identified.

Automated Translation from French
Dislike

From the user's (non-administrator's) point of view, no blocking points have been identified.

Automated Translation from French