• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Cortex XDR
Logo of Cortex XDR

Cortex XDR

byPalo Alto Networks
in
4.6
2025
Market Presence: Endpoint Protection Platforms, Extended Detection and Response

Overview

Product Information on Cortex XDR

Updated 13th October 2025

What is Cortex XDR?

Cortex XDR is a software developed by Palo Alto Networks that integrates data from network, endpoint, and cloud sources to detect, investigate, and respond to cyber threats. The software enables security teams to identify suspicious behavior, conduct root cause analysis, and respond to incidents through automated response capabilities. It provides analytics-driven threat prevention and leverages behavioral analytics to correlate alerts across different environments, helping organizations reduce risks from advanced attacks. Cortex XDR addresses challenges of fragmented security data and manual threat investigations by consolidating security operations into a single platform, allowing for more efficient detection and response workflows.

Cortex XDR Pricing

Cortex XDR software utilizes a subscription-based pricing model, where charges are typically determined by factors such as number of endpoints, data ingestion volume, or user count. Pricing varies according to the chosen features, deployment scale, and support options, with additional costs for advanced capabilities and integrations. Licenses are available in different tiers to address varying organizational needs for threat detection and incident response.

Overall experience with Cortex XDR

Security Engineer
500M - 1B USD, Services (non-Government)
FAVORABLE

“Low False Positives and Straightforward SIEM Integration Highlight EDR Solution Experience”

4.0
Jan 23, 2026
Clear leader in EDR solutions on the market currently from what we have evaluated, noise-ratio on false positives are fairly low. Fairly straightforward integration with our SIEM solution. Only noticeable issue is the seldom performance issues caused by the agents themselves, however these are not frequent.
Manager, IT Security and Risk Management
3B - 10B USD, Healthcare and Biotech
CRITICAL

“Palo Alto Cortex XDR - While A Great Product, Be Extremely Wary of Price Increased”

3.0
Dec 28, 2023
We implemented Cortex XDR when it was still called Traps. Palo Alto acquired the product and we initially struggled with engineering resources trying get the toolset to meet our EDR needs. After more than a year of back and forth and multiple escalations, we were in a decent spot. The product works as intended and provided us insights into the endpoints that we previously did not have with traditional AV. The biggest issue with Palo is price point. While the initial 3-year contract had a great rate, the renewal charges were increased by 225%. They assumed all customers will just eat those large costs since they are so intertwined in the environment.

Badges

Gartner Peer Insights recognizes vendors who meet or exceed both the market average Overall Experience and the market average User Interest and Adoption score through a Customers’ Choice distinction.
2025
For Market:
Mobile Threat Defense

About Company

Company Description

Updated 7th December 2023

Palo Alto Networks is a global cybersecurity organization shaping the future of cloud-centric technology. The main business objective is to provide effective cybersecurity solutions, maintaining and valuing the digital way of life. It addresses the significant issue of maintaining digital security in an increasingly online-centric world. The company utilizes innovative approaches leveraging advancements in artificial intelligence, analytics, automation, and orchestration. Offering an integrated platform and bolstering a burgeoning ecosystem of collaborators, it assures protection across various platforms including clouds, networks, and mobile devices. The organization envisions a progressively safe and secure digital world each day.

Company Details

Updated 1st July 2025
Company type
Public
Year Founded
2005
Head office location
SANTA CLARA, United States
Number of employees
10001+
Website
http://www.paloaltonetworks.com

Do You Manage Peer Insights at Palo Alto Networks?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Cortex XDR
Reviewer Insights for: Cortex XDR
Deciding Factors: Cortex XDR Vs. Market Average
Performance of Cortex XDR Across Market Features

Cortex XDR Likes & Dislikes

Like

Ease of use, specifically handling host isolations to perform investigations on potential true positives. SIEM and SOAR integration works well for some of our automations/playbooks.

Like

The flexibility of the solution is what kept us happy with this solution. Palo eventually started working closely with our organization to add features that would improve the product, not just for us, but for all their customers. The interface is intuitive and can be picked up very quickly with minimal training.

Like

Palo Alto Cortex XDR has many features like Cortex XDR detects sophisticated threats, including zero-day exploits. Cortex XDR scales to meet the needs of large enterprise environments.

Dislike

Seldom performance impact, central management of the suite of services in the cloud console can sometimes be a pain. Customer support can also be improved, we have found that shifting support to different regions does have a substantial positive impact.

Dislike

The customer service is the worst part of Palo Alto. They are such a large company that they are not willing to listen to the issues that customers have. Another issue is RBAC. It is overly complicated, especially if you have multiple Palo products.

Dislike

Some weaknesses are that the endpoint agent can be resource-intensive, especially on older hardware, causing a slowdown. Some users have reported that the Web console can be slow, glitchy and time out. Cortex XDR is often very expensive for smaller organizations.

Top Cortex XDR Alternatives

Logo of CrowdStrike Falcon
1. CrowdStrike Falcon
4.7
(2997 Ratings)
Logo of SentinelOne Singularity Endpoint
2. SentinelOne Singularity Endpoint
4.7
(2855 Ratings)
Logo of Sophos Endpoint
3. Sophos Endpoint
4.8
(2052 Ratings)
View All Alternatives

Peer Discussions

Cortex XDR Reviews and Ratings

Showing data for 638 ratings and reviews for Endpoint Protection Platforms market. View all 738 ratings and reviews across markets for a complete picture.

4.6

(638 Ratings)

Rating Distribution

5 Star
62%
4 Star
35%
3 Star
3%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.6

Integration & Deployment

4.6

Service & Support

4.6

Product Capabilities

4.7

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • Security Engineer
    50M-1B USD
    Services (non-Government)
    Review Source

    Low False Positives and Straightforward SIEM Integration Highlight EDR Solution Experience

    4.0
    Jan 23, 2026
    Clear leader in EDR solutions on the market currently from what we have evaluated, noise-ratio on false positives are fairly low. Fairly straightforward integration with our SIEM solution. Only noticeable issue is the seldom performance issues caused by the agents themselves, however these are not frequent.
  • Bdm
    50M-1B USD
    IT Services
    Review Source

    Strong Protection Features Balanced by Expensive Cost and Performance Drawbacks

    5.0
    Jan 26, 2026
    Overall experience is very good because they provide strong threat detection, prevention, automation, and SOC support. They also provide centralized visibility and analytics.
  • Senior Security Architect
    50M-1B USD
    Energy and Utilities
    Review Source

    Detect faster. Respond smarter

    5.0
    Feb 3, 2026
    Excellent capacity of detection and continuous improvement
  • MANAGER, IT SECURITY AND RISK MANAGEMENT
    <50M USD
    IT Services
    Review Source

    Cortex XDR Provides Advanced Threat Protection but Support Response Delayed

    5.0
    Dec 2, 2025
    The cortex XDR has advanced features. We have been using the protection for a long time. It blocks the threat based on the realtime signature. We can get the logs from various network devices.
  • IT Manager
    50M-1B USD
    Energy and Utilities
    Review Source

    Intuitive Dashboard and Threat Investigation Noted, but Pricing Remains a Concern

    5.0
    Oct 28, 2025
    Overall, the platform is easy to configure and contains robust security policies, allowing it to stay ahead of other products on the market that sell these features separately.
...
Showing Result 1-5 of 657

Recommended Gartner Research

  • Critical Capabilities for Endpoint Protection Platforms
  • Magic Quadrant for Endpoint Protection Platforms

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.