Best Extended Detection and Response (XDR) Platforms - Page 6

How Many Extended Detection and Response (XDR) Platforms Products Does G2 Track?

Total Products under this Category: 103

Category Stats (Sep 2026)

  • Average Rating: 4.55/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Singularity AI SIEM (+3.53%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Extended Detection and Response (XDR) Platforms Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 6,500+ Authentic Reviews
  • 103+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Extended Detection and Response (XDR) Platforms

G2 Grid® for Extended Detection and Response (XDR) Platforms plotting products by satisfaction and market presence

Highlighted products: Sophos Endpoint, CrowdStrike Falcon Endpoint Protection Platform, CrowdStrike Falcon Cloud Security, TrendAI Vision One, Check Point Endpoint Security, ESET PROTECT, Cynet, and SentinelOne Singularity Endpoint.

Underlying data: [Grid® JSON](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms/grids.json?focus%5B%5D=sophos-endpoint&focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=trendai-vision-one&focus%5B%5D=check-point-endpoint-security&focus%5B%5D=eset-protect&focus%5B%5D=cynet&focus%5B%5D=sentinelone-singularity-endpoint)

GoSecure Titan Managed Security Platform

While GoSecure Professional Security Services focuses on finding the problems, GoSecure Titan® Managed Security Services make sure to solve them – making GoSecure your ally to consolidate, evolve & thrive. Our service offering includes: • GoSecure Titan® Managed Extended Detection & Response (MXDR) which offers the best-in-class 15-minute response time from threat detection to mitigate with a solution that identifies, blocks, & reports potential breaches. • GoSecure Titan® Vulnerability Management as a Service (VMaaS) helps defend against the constantly changing threat landscape by continuously identifying critical assets, threats and vulnerabilities and working quickly to remediating threats as they arise allowing businesses to get more value from their security and IT operations. • GoSecure Titan® Managed Security Information and Event Monitoring (SIEM) offers advanced security intelligence, comprehensive incident handling, simplified compliance, scalability, threat intelligence integration, and optimized security operations. • GoSecure Titan® Managed Perimeter Defense (MPD) helps organizations address the challenge of monitoring and managing their firewall infrastructure. Whether a single firewall, or hundreds, GoSecure has the skills and resources to manage any size environment. Operating 24x7x365, the GoSecure Security Operations Center (SOC) provides global coverage to keep your firewalls operating at peak efficiency. • GoSecure Titan® Inbox Detection & Response (IDR) gives every user the ability to test any suspicious email. They can finally stop worrying about missing threats, wasting time wondering what to do, or worrying about “crying wolf” too often. With a simple click, employees now become a united force against phishing. GoSecure Titan® IDR is the perfect solution to remediate the phishing problem. Enhance your organization’s cyber defense capabilities GoSecure Titan® Managed Security Services provides industry-leading response and mitigation speeds, essential in today’s rapidly evolving threat landscape. Our services are designed to keep your business safe and secure, ensuring peace of mind in the face of growing cyber threats.

Average Rating: 3.0/5.0

Total Reviews: 1

Who Is the Company Behind GoSecure Titan Managed Security Platform?

  • Seller: GoSecure Inc.
  • Company Website:
  • Year Founded: 2002
  • HQ Location: La Jolla, US
  • Twitter: @GoSecure_Inc
    2,742 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    161 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

Hakware

Who Is the Company Behind Hakware?

Heimdal XDR

Who Is the Company Behind Heimdal XDR?

  • Seller: Heimdal®
  • Year Founded: 2014
  • HQ Location: Copenhagen, Denmark
  • Twitter: @HeimdalSecurity
    5,086 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    284 employees on LinkedIn®

Hexnode XDR

Hexnode XDR is an extended detection and response (XDR) software solution designed to help organizations detect, investigate, and respond to security threats across managed endpoints from a centralized platform. It consolidates endpoint telemetry and security signals to provide contextual visibility into potential threats, enabling security and IT teams to take timely and informed action. Hexnode XDR is primarily used by IT administrators and security teams that need greater visibility into endpoint activity and a structured way to investigate and contain security incidents. By correlating endpoint data in real time, the platform helps reduce alert noise and supports faster identification of suspicious behaviour across devices. The solution extends beyond traditional endpoint detection and response (EDR) by providing a more holistic view of security events. Hexnode XDR also supports automated and manual response actions to help contain threats efficiently. Security teams can define response workflows or take direct action from a unified console, reducing investigation time and minimizing the potential impact of security incidents. The platform is designed to integrate smoothly into existing endpoint management workflows, making it suitable for organizations looking to strengthen endpoint security while maintaining operational efficiency. Key Features Include: Real-time Endpoint Visibility: Continuous monitoring of all managed endpoints to ensure total transparency. Advanced Threat Hunting: Proactively search for hidden indicators of compromise (IoCs) across the environment. Contextual Alerting: Intelligent correlation of security events to reduce alert fatigue and prioritize critical incidents. One-Click Remediation: Instantly isolate devices, terminate malicious processes and quarantine suspicious files. Unified Security Console: Manage detection, investigation, and response without switching between multiple platforms. Hexnode UEM Integration: Allows security teams to align threat response with endpoint policies and device controls

Who Is the Company Behind Hexnode XDR?

  • Seller: Mitsogo Inc.
  • Year Founded: 2013
  • HQ Location: San Francisco, CA
  • Twitter: @thehexnode
    17,615 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    532 employees on LinkedIn®

Huntsman Next Gen SIEM

Huntsman Security’s Next Gen SIEM is a cyber security analytics product with built-in threat intelligence and behaviour anomaly detection, designed to analyse high volume streams of data in real-time to quickly and accurately detect non-compliant system activity, anomalous behaviour, security issues and cyber threats.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Huntsman Next Gen SIEM?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)

Who Is the Company Behind Huntsman Next Gen SIEM?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Huntsman Next Gen SIEM?

Kaspersky Industrial CyberSecurity

Native Extended Detection and Response (XDR) platform for critical infrastructure protection. Purpose-built platform delivering multi-layered protection for operational technology (OT) environments. • Infrastructure visibility. Track all connected devices and their configurations. Build a network graph and analyze data flows • Threat elimination. Mitigate threats across hosts and networks, with insights into root causes and safe response measures •Risk assessment. Assess vulnerabilities and check security settings changes for hosts, network devices and controllers Kaspersky Industrial CyberSecurity features natively integrated nodes and network security products for protection of modern and legacy OT assets, automation and control systems, without affecting technological process or system availability. • Kaspersky Industrial CyberSecurity for Networks monitors and analyses industrial network traffic to provide full-fledged visibility into industrial assets and communications. By identifying anomalies and intrusions in the OT infrastructure at an early stage, KICS for Networks helps prevent any negative impact on industrial processes. • Kaspersky Industrial CyberSecurity for Nodes is a low-footprint solution that ensures security of each and every Windows and Linux system within today’s diverse industrial environments. It combines traditional endpoint protection with OT-specific controls. KICS for Nodes is also available as a portable, installation-free scanner for sensitive, isolated or legacy machinery and  bring-in contractors’ devices.

Who Is the Company Behind Kaspersky Industrial CyberSecurity?

  • Seller: Kaspersky
  • Year Founded: 1997
  • HQ Location: Moscow
  • Twitter: @kasperskylabind
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,616 employees on LinkedIn®
  • Phone: 1-866-328-5700

Nozomi Networks Platform

Nozomi Networks offers highly accurate, actionable intelligence and protection for integrated cybersecurity at scale. The detailed visibility and in-depth insight provided by Nozomi Networks lets users: • See all the OT, IoT, IT, edge and cloud assets on your networks • Pinpoint the cyber threats and vulnerabilities that matter most • Respond quickly to incidents with forensic analysis tools • Manage asset, security and network data in a single platform • Scale cyber and operational resilience across your entire infrastructure

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Nozomi Networks Platform?

  • Has the product been a good partner in doing business?: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Nozomi Networks Platform?

  • Seller: Nozomi Networks
  • Year Founded: 2013
  • HQ Location: San Francisco, California, United States
  • Twitter: @nozominetworks
    4,238 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    365 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Nozomi Networks Platform?

AI-generated summary from verified user reviews

Pros
  • Users highlight the customization features of Nozomi Networks Platform, enhancing their ability to monitor network activities effectively.
  • Users value the effective detection algorithms of Nozomi Networks Platform, which accurately identify intrusions and malicious traffic.
  • Users commend the detection efficiency of Nozomi Networks Platform, effectively identifying intrusions and analyzing traffic patterns.
  • Users value Nozomi's detection algorithms for identifying intrusions and its excellent interface for traffic pattern visualization.
  • Users value the advanced threat detection capabilities of Nozomi Networks, identifying intrusions and malicious traffic effectively.
Cons
  • Users find the Nozomi Networks Platform expensive, yet it aligns with cybersecurity budget constraints against competitors.

What Are Recent G2 Reviews of Nozomi Networks Platform?

nPro AI

Npro AI is a converged security platform that unifies Extended Detection and Response (XDR) with Security Information and Event Management (SIEM). It provides a single point of truth for threat detection, incident response, and regulatory compliance across on-premises, cloud, and containerized environments. By combining Log Data Analysis with File Integrity Monitoring (FIM) and Vulnerability Detection, Npro AI offers deep visibility into system changes and security posture. The platform is designed for active defense, utilizing an Active Response engine to automatically block malicious connections or terminate processes in real-time.

Who Is the Company Behind nPro AI?

OpenText Core MDR (Managed Detection & Response)

Rapid changes in the cyber threat landscape require organizations to uncover hidden risks and threats before they have an impact on the bottom line, operations and reputation. Organizations can no longer rely on perimeter defenses for network security, especially against pernicious ransomware attacks. In addition, many security teams don't have the resources required to effectively monitor security alerts or detect and respond against advanced threats.

Who Is the Company Behind OpenText Core MDR (Managed Detection & Response)?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

OpenText Cybersecurity Aviator

OpenText™ Cybersecurity Aviator™ is an advanced AI-driven solution designed to revolutionize threat detection and enhance organizational security postures. By leveraging machine learning models that continuously learn and adapt, it enables rapid deployment of new threat detection models within hours, effectively protecting against both known and emerging cyber threats. Key Features and Functionality: - AI-Powered Threat Detection: Utilizes unsupervised machine learning to identify and classify cyber threats by analyzing vast amounts of security events, uncovering hidden behavior-based patterns. - Rapid Deployment: Facilitates the swift implementation of new threat detection models, ensuring organizations can respond to evolving threats promptly. - Continuous Learning: Employs machine learning models that automatically and continuously learn, enhancing the accuracy and effectiveness of threat detection over time. - Scalability and Flexibility: Offers cloud-based efficiency, allowing organizations to scale their security operations seamlessly without significant infrastructure changes. Primary Value and Problem Solved: OpenText Cybersecurity Aviator addresses the critical need for agile and effective threat detection in an era of rapidly evolving cyber threats. Traditional threshold-driven methods often fall short in identifying sophisticated attacks. By integrating AI and machine learning, Cybersecurity Aviator provides organizations with a proactive defense mechanism that adapts to new threats as they emerge, significantly reducing the time to detect and respond to incidents. This not only enhances the overall security posture but also alleviates the burden on security teams, allowing them to focus on strategic initiatives rather than being overwhelmed by false positives and manual threat analysis.

Who Is the Company Behind OpenText Cybersecurity Aviator?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

OpenText Secure Cloud​

OpenText Secure Cloud is a comprehensive, cloud-native platform designed to streamline cybersecurity management for Managed Service Providers (MSPs) and Small to Medium-sized Businesses (SMBs). By consolidating account management, license provisioning, security insights, and threat response into a single interface, Secure Cloud simplifies operations, allowing businesses to focus on growth and delivering exceptional services. Key Features and Functionality: - Centralized Management: Manage products, licenses, and billing through a unified platform, enhancing operational efficiency and oversight. - Customizable Bundles: Offer tailored security solutions with flexible, customizable bundles that meet diverse client needs. - API and PSA Integrations: Seamlessly connect with platforms like Kaseya, Autotask, ConnectWise, and HaloPSA to simplify billing and management processes. - Integrated Dashboard: Utilize intuitive tools such as an order history page, customer events calendar, and task alerts to manage tasks, customers, and orders effortlessly. - Customer Relationship Management: Leverage integrated tools like event calendars and renewal alerts to maintain and strengthen client relationships. - Cost Reduction and Margin Enhancement: Automate tasks, unify billing, and implement bundled solutions to deliver greater value to clients while reducing operational costs. Primary Value and Solutions Provided: OpenText Secure Cloud addresses the complexities of cybersecurity management by offering a centralized, user-friendly platform that enhances operational efficiency and scalability. For MSPs, it simplifies service delivery, enabling them to provide comprehensive security solutions with ease. SMBs benefit from robust protection and streamlined operations, allowing them to focus on core business activities without the burden of managing multiple security tools. By integrating various functionalities into a single platform, Secure Cloud reduces overhead, improves service consistency, and supports business growth.

Who Is the Company Behind OpenText Secure Cloud​?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Percept XDR

Percept XDR ensures end-to-end security, threat detection and response while allowing enterprises to focus on their core business growth without the fear of compromise. Percept XDR helps to protect against phishing, ransomware, malware, vulnerability exploits, insider threats, web attacks and many more advanced attacks. Percept XDR features SOAR-based automated response in line with the MITRE ATT&CK framework. The reduced number of incidents that require manual intervention allows enterprise IT teams to focus on the core objectives.

Who Is the Company Behind Percept XDR?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024