---
title: Cortex XDR Reviews
meta_title: 'Cortex XDR Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 84 reviews by the users' company size, role or industry to
  find out how Cortex XDR works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 84
  scale: '5'
date_modified: '2026-08-04'
parent_category:
  name: Cloud Security
  url: https://www.g2.com/categories/cloud-security
---

# Cortex XDR Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Extended Detection and Response (XDR) Platforms](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 84
## About Cortex XDR
Cortex XDR is the industry’s first extended detection and response platform that stops modern attacks by integrating data from any source. With Cortex XDR, you can harness the power of AI, analytics and rich data to detect stealthy threats. Your SOC team can cut through the noise and focus on what matters most with intelligent alert grouping and incident scoring. Cross-data insights accelerate investigations, so you can streamline incident response and recovery. Cortex XDR delivers peace of mind with best-in-class endpoint protection that achieved the highest combined protection and detection scores in the MITRE ATT&amp;CK® round 3 evaluation. The Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic protection to secure what’s next.



## Cortex XDR Pros & Cons
**What users like:**

- Users value the **important alert notifications** from Cortex XDR, which enhance security without overwhelming them. (2 reviews)
- Users appreciate the **simplicity and manageability** of Cortex XDR, finding it easy to navigate and utilize effectively. (2 reviews)
- Users love the **unique features** of Cortex XDR, especially its effective threat detection without compromising system speed. (2 reviews)
- Users praise the **unified detection and response capability** of Cortex XDR, enhancing threat investigation efficiency and accuracy. (2 reviews)
- Users value the **unified detection and response capability** of Cortex XDR for swift and precise threat investigations. (2 reviews)
- AI (1 reviews)
- AI Technology (1 reviews)
- Alerting (1 reviews)
- Alerts (1 reviews)
- Users appreciate the **effective antivirus protection** of Cortex XDR, as it quickly detects and handles various threats. (1 reviews)

**What users dislike:**

- Users find **limited features** in Cortex XDR, with restrictions affecting core OS functionalities and usability issues on lower-end systems. (2 reviews)
- Users experience a **noticeable performance impact** on lower-end systems with the Cortex XDR agent installed. (1 reviews)
- Users face **compatibility issues** with Cortex XDR, restricting core functionalities and software installations on their machines. (1 reviews)
- Users find the **system complexity** challenging, often struggling with management and a steep learning curve. (1 reviews)
- Users find the **complex management** of Cortex XDR challenging due to its steep learning curve and customization difficulties. (1 reviews)
- Users find the **difficult learning curve** challenging, especially when managing policies and customizing detections in Cortex XDR. (1 reviews)
- Users find the Cortex XDR to be **expensive** for public school systems, but value its worth despite the cost. (1 reviews)
- Users note the **restrictive core functionalities** of Cortex XDR, limiting certain installations and affecting usability. (1 reviews)
- High Resource Usage (1 reviews)
- Users face **installation difficulties** with Cortex XDR, as it restricts some core OS functionalities during setup. (1 reviews)

## Cortex XDR Reviews
  ### 1. Robust Threat Detection, But a Steep Learning Curve

**Rating:** 4.0/5.0 stars

**Reviewed by:** Dev S. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

What I like most about Cortex XDR is how it connects the dots between tiny, suspicious events and the bigger attack story they're part of. That correlation view saves a lot of guesswork, and the behavioral detections tend to catch weird stuff early, even when there's no clear signature. It just feels like it gives us clarity when things are tried to state.

**What do you dislike about Cortex XDR?**

I find the interface feels a little dense, with too many panels and options at once. As a new analyst, I feel overwhelmed until I get used to it. Also, it takes me time to get the alert tuning right because the alerts can be a bit noisy out of the box until I fine-tune the policy.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps us spot hidden threats that normal antivirus tools miss, like ransomware and fileless attacks. It correlates endpoint and network data, cutting investigation time and providing a clear path to contain devices and respond quickly before damage spreads.

  ### 2. A robust XDR platform which simplifies Threat Investigation

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ajeet  U. | Security Lead Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Cortex XDR?**

The user inerface is very well designed. The integrations is very easy in comparision of other third party security tools.
In performance prospective, The Endpoint agent is very lightweight and it consume minimal resouces on system in comparision of other security tools.
The cortex XDR provides premium service of XDR solution. it is a cost effective solution for any company/organizations that give priority strong security .
The support service is great and effecrive related to any troubleshooting or integrations. It has AI driven analytics and ML capabilities, which help detect unknown threats, risks and fileless attacks.

**What do you dislike about Cortex XDR?**

The licensing cost can be high for small or startup organizations or companies and the initialy setup and policy creation/policy tuning require experienced engineer or administrators

**What problems is Cortex XDR solving and how is that benefiting you?**

It i talk about Cortex XDR, detections and response for threats are very faster and it reduce the alerts fatigue and it improve SOC efficiency for centralised detections/ visibility.

  ### 3. Solid detection depth, but plan for a learning curve

**Rating:** 4.5/5.0 stars

**Reviewed by:** Joshuva A. | Cybersecurity Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Cortex XDR?**

We tested Cortex XDR as a proof of concept before committing to anything, and rolled the agent out to about 10 endpoints for roughly six weeks. What won me over was the incident view: instead of chasing a bunch of separate alerts, it pulled everything related into a single incident, complete with a process tree, so I could clearly see what happened and in what order. That saved a ton of back-and-forth.

The behavioral detection also caught a couple of the sneakier things we tested it with that I wasn’t sure it would pick up. XQL took a bit to get used to, but once it clicked, being able to hunt across endpoint and network data from one place was really handy. If your main priority is detection depth, that part feels solid.

**What do you dislike about Cortex XDR?**

Honestly, there’s a bit of a learning curve. Getting comfortable with XQL and tuning it properly for our environment took longer than I expected, and the console can feel pretty busy when you’re just starting out. Rolling out the agent also took a few attempts before we got the policies set up the way we wanted. On top of that, sorting out pricing was more of a hassle than it should have been, it took some back-and-forth to understand what a full deployment would actually cost us. None of this killed the eval, but it’s the kind of friction a smaller team should know about going in.

**What problems is Cortex XDR solving and how is that benefiting you?**

We were mainly trying to confirm whether having endpoint and network detection in one place would actually reduce our investigation time. During the test, the correlation piece stood out most, grouping related alerts into a single incident meant far less manual digging to understand the scope and what was connected. Since this was an evaluation and not a full rollout, I’d say it looked very promising in that area, without trying to claim any long-term results or numbers.

  ### 4. Top-Notch Security with Streamlined Incident Response

**Rating:** 4.5/5.0 stars

**Reviewed by:** Nilesh K. | Senior Security Engineer, Computer & Network Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Cortex XDR?**

I am using Cortex XDR to secure our business infrastructure. It provides a NextGen antivirus that effectively blocks malware, ransomware, and other types of exploits and attacks. I like how it can correlate alerts from endpoints, networks, and other sources into a single management console and helps detect advanced threats like zero-day exploits. It's easy to get root cause analysis and identify attack patterns. Cortex XDR helps reduce the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) during investigations and responses to stakeholders in one place, which is very important because every second counts in cybersecurity. Deploying agents and configuring security profiles, firewall connectivity, and cloud infra tuning are all well-documented and easy to do.

**What do you dislike about Cortex XDR?**

I find that I need proper training to use Cortex XDR effectively as a new analyst.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR for securing our business infrastructure. It blocks malware, ransomware, and exploits, correlates alerts in a single console, and detects advanced threats like zero-day exploits. It helps reduce MTTD and MTTR, making incident analysis and getting to root causes easier.

  ### 5. Powerful Security Tool with a Complex UI

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jaqueline V. | Student Software Developer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Cortex XDR?**

I like Cortex XDR for its ability to connect related security events and patterns into an incident review, which helps analysts like me understand the full story behind an alert. This capability improves the quality of the labeled data and enhances analysis accuracy despite the initial complexity of the interface.

**What do you dislike about Cortex XDR?**

I find that the platform provides too much security data, making it hard for me to identify important information quickly. Improving the organization of alert details, prioritizing key events, and providing clearer summaries would help me work more efficiently. A more customizable alert summary view that highlights the most important details at the beginning of an investigation could really streamline my process, offering a quick overview of key factors like the affected endpoint, user activity, process behavior, file reputation, network connections, and so on.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to review security alerts, improving labeled data quality by providing endpoint visibility and connecting security events for better analysis.

  ### 6. Reliable XDR Platform for Security Teams

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I like the strong threat detection and security visibility provided by Cortex XDR. It helps identify suspicious activities quickly and gives a clear view of incidents from one platform. The automated investigation features and real-time alerts help the security team respond faster. The dashboard is easy to understand, and integrations with other security tools improve overall workflow and efficiency.

**What do you dislike about Cortex XDR?**

The initial setup and configuration can take some time, especially for new users. Some advanced features may require extra learning and security knowledge to use properly. The interface is powerful, but a few areas could be made simpler to improve the experience for beginners. More detailed guidance and easier troubleshooting options would make the platform even better.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to detect threats and protect our endpoints, helping us detect threats early and respond faster. It saves time with quick threat detection and clear alerts, making it easy to use and valuable for fast response.

  ### 7. Streamlined Threat Detection with Some Setup Challenges

**Rating:** 4.5/5.0 stars

**Reviewed by:** Rohit B. | Assistant Manager - Endpoint Security, Insurance, Enterprise (> 1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I like Cortex XDR for its noise reduction and automation, which saves time for the analysts. Its scalability and simplicity stand out to me. The faster root cause analysis with Cortex XDR improves the efficiency of our analysts and helps in simplifying operations. I also appreciate the readiness it provides.

**What do you dislike about Cortex XDR?**

The initial setup of Cortex XDR was quite complex for me, especially since the rollout was tedious and the policy tuning was very difficult due to our large environment. I found that training is often needed when new features are introduced, which can be challenging to keep up with. Additionally, I've faced integration challenges with third-party tools. The costs can also be an issue, and negotiating the bundle or selectively deploying add-ons is necessary to manage them effectively.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to reduce alert noise and improve endpoint protection. It addresses issues like fragmented visibility and slow response, enhancing analyst efficiency and simplifying operations through automation and scalability, leading to faster root cause analysis and improved readiness.

  ### 8. Causality Engine Delivers Fast, End-to-End Attack Visibility

**Rating:** 4.0/5.0 stars

**Reviewed by:** Amaan M. | Soc Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The endpoint agent and the causality engine really stand out for us. We came from a traditional EDR that generated a flood of separate alerts, so XDR’s ability to tie process, network, and user activity together into a single causal chain has been a big improvement. It lets analysts see the full story of an attack instead of piecing together fragments. Root-cause analysis that used to take an hour of pivoting now takes just minutes.

**What do you dislike about Cortex XDR?**

The management console has a steep learning curve. There are many nested menus, and finding specific settings or policies isn’t always intuitive. New analysts need real ramp-up time before they can be productive in the UI. Some workflows also require jumping between different sections of the console more than they should, which slows things down. Reporting is another weak spot. The built-in reports cover the basics, but anything customized for executive or compliance audiences typically means exporting data and building it elsewhere.

**What problems is Cortex XDR solving and how is that benefiting you?**

The biggest value XDR brings is unified visibility across endpoints, networks, and identities, which eliminates fragmented alerts and the need for manual correlation. Its causality engine automatically links related events into a single incident, giving analysts a clear view of the full attack chain rather than a set of isolated alerts. This can significantly reduce investigation time and support faster triage and containment. In parallel, the unified agent brings prevention, EDR, and host controls together in one solution, helping reduce tool sprawl, endpoint overhead, and day-to-day operational complexity. Overall, the result is better analyst efficiency, stronger security operations, and lower management overhead.

  ### 9. Strong Correlation and Investigation Depth for SOC-Scale Threat Hunting

**Rating:** 4.0/5.0 stars

**Reviewed by:** Alessandro D. | Technical Leader, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

Cortex XDR stands out in day-to-day SOC operations for how effectively it correlates endpoint, network, and cloud telemetry into a single investigative view. As a Technical Lead managing a team of five analysts, I find the incident timeline and causality-chain visualization especially valuable for threat hunting and incident response—it significantly reduces the time needed to reconstruct an attack path versus piecing together logs across siloed tools. The behavioral analytics engine is also strong at detecting living-off-the-land techniques and lateral movement that signature-based tools often miss. Integration with the broader Cortex ecosystem (especially XSOAR for orchestration) further helps by enabling automation of repetitive triage steps, which is particularly important when maintaining H24 on-call coverage.

**What do you dislike about Cortex XDR?**

The learning curve to fully master the platform is steeper than with some competing EDR/XDR solutions, especially when it comes to fine-tuning detection rules to cut down on noise without sacrificing coverage. New analysts on the team need meaningful ramp-up time before they’re fully productive. Licensing and add-on module costs can also add up quickly if you want full XDR capability (network, cloud, identity) rather than endpoint-only coverage. Occasionally, the alert-correlation logic feels opaque, which makes it harder to explain in post-incident reporting why certain events were grouped together.

**What problems is Cortex XDR solving and how is that benefiting you?**

It’s a core part of our detection and response stack, helping us reduce mean time to detect and respond to incidents by consolidating multiple data sources that analysts would otherwise have to hunt through manually. It’s especially useful for correlating phishing-driven incidents with subsequent endpoint activity, and it also supports our escalation workflows during the 24/7 on-call rotation.

  ### 10. Cortex XDR: High-Quality Threat Detection and Fast, Centralized Investigations

**Rating:** 5.0/5.0 stars

**Reviewed by:** A K M Abdullah A. | Founder &amp; Chief Visionary Officer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 17, 2026

**What do you like best about Cortex XDR?**

High-quality threat detection: It uses behavioral analytics and AI to identify malware, ransomware, and other advanced threats beyond traditional signature-based antivirus. Reduced alert fatigue: It groups related alerts into incidents, which helps security analysts focus on the most important threats instead of reviewing hundreds of isolated events. Fast investigation: It provides detailed process trees, timelines, and correlated evidence so analysts can quickly understand how an attack unfolded. Centralized visibility: It offers a single console for monitoring endpoints and other security data, making day-to-day operations more efficient. Strong integration with the Palo Alto ecosystem: Organizations already using Palo Alto firewalls or other Cortex products typically get the most value from the platform. Cortex XDR has performed well in situations where rapid threat detection and response are critical. The platform provides strong visibility across endpoints and other security data sources, allowing our team to quickly identify suspicious activity and understand the full scope of an incident. Its alert correlation capabilities help reduce noise by grouping related events into a single incident, which saves valuable investigation time and enables analysts to focus on higher-priority threats.

In day-to-day operations, Cortex XDR has helped streamline security monitoring and incident response workflows. The detailed investigation tools, including process trees and attack timelines, make it easier to determine root causes and assess impact. This has improved our team's efficiency and reduced the time required to contain and remediate potential threats.

While there is a learning curve to fully leverage advanced features and analytics, the overall benefits in threat visibility, detection accuracy, and response speed have made it a valuable part of our security operations. It has been particularly effective in helping us identify unusual behavior, investigate incidents faster, and maintain a stronger security posture across the organization. Cortex XDR has performed well in situations where rapid threat detection and response are critical. The platform provides strong visibility across endpoints and other security data sources, allowing our team to quickly identify suspicious activity and understand the full scope of an incident. Its alert correlation capabilities help reduce noise by grouping related events into a single incident, which saves valuable investigation time and enables analysts to focus on higher-priority threats.

In day-to-day operations, Cortex XDR has helped streamline security monitoring and incident response workflows. The detailed investigation tools, including process trees and attack timelines, make it easier to determine root causes and assess impact. This has improved our team's efficiency and reduced the time required to contain and remediate potential threats.

While there is a learning curve to fully leverage advanced features and analytics, the overall benefits in threat visibility, detection accuracy, and response speed have made it a valuable part of our security operations. It has been particularly effective in helping us identify unusual behavior, investigate incidents faster, and maintain a stronger security posture across the organization.

**What do you dislike about Cortex XDR?**

One thing I don’t like about Cortex XDR is that it can come with a fairly steep learning curve, particularly for new analysts who want to fully take advantage of its advanced investigation and query capabilities. The initial setup and policy tuning can also take considerable time and expertise, especially when trying to optimize detections while keeping false positives to a minimum. On top of that, some organizations may find the licensing structure and advanced feature add-ons a bit complicated to understand and manage.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps us address the challenge of detecting and investigating threats across multiple security layers by giving us centralized visibility into endpoint, network, cloud, and user activity. Rather than manually correlating alerts from different tools, the platform automatically groups related events into incidents, which improves detection accuracy and reduces alert fatigue. As a result, our team can respond to security incidents faster, spend less time on manual investigations, and maintain clearer visibility into potential threats across the environment.

  ### 11. Premium Price and Steep Learning Curve, Despite Strong AI Threat Detection

**Rating:** 2.5/5.0 stars

**Reviewed by:** Brauny N. | Site Reliability Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** July 15, 2026

**What do you like best about Cortex XDR?**

The UI is clean and the single console makes investigations fast, though the sheer number of settings can feel dense at first. Integrations are a strong point, it pulls endpoint, network, and cloud data together and plays well with the rest of the Palo Alto stack plus third-party feeds. Performance is solid, the agent is lightweight and doesn't drag down endpoints, and queries return quick even across large data sets.
Pricing sits on the higher end, but the ROI holds up once you factor in the tools it replaces and the analyst hours saved on triage. Support and onboarding were smooth, the deployment guidance was clear and response times good, though full tuning takes a few weeks. The AI and threat intel is the standout, behavioral analytics and causality analysis surface real threats with low false positives and cut down manual digging.

**What do you dislike about Cortex XDR?**

The price is the main sticking point, it's a premium product and the licensing adds up fast, especially as you scale endpoints or add modules. The learning curve is real too, the console packs a lot in and getting alerts tuned the way you want takes time upfront.
A few other gripes: initial setup and policy configuration can feel heavy, some advanced features are gated behind higher tiers, and the reporting could be more flexible without exporting to build custom views. Occasional agent updates have needed babysitting. None of it is a dealbreaker, but the cost and ramp-up are worth going in aware of.

**What problems is Cortex XDR solving and how is that benefiting you?**

It replaced a patchwork of separate endpoint, network, and detection tools with one platform, so we're no longer pivoting between consoles or trying to correlate alerts by hand. Everything lands in a single incident view.

The big benefit is speed. Causality analysis shows the full attack chain and root cause, so triage that used to take hours now takes minutes. False positives are low, so the team spends time on real threats instead of chasing noise, and consolidating tools has cut both cost and management overhead.

  ### 12. Outstanding Visibility and Threat Detection with Cortex XDR

**Rating:** 5.0/5.0 stars

**Reviewed by:** Daniel Q. | Math Teacher, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 01, 2026

**What do you like best about Cortex XDR?**

After working with Cortex XDR, I can definitely see why it’s considered one of the leading XDR solutions. The visibility, threat detection, and response capabilities are outstanding.

**What do you dislike about Cortex XDR?**

What I dislike about Cortex XDR is that it can feel overly complex for everyday use. There are so many features and settings that it sometimes takes longer than it should to find what I'm looking for. While it's powerful, I don't think the interface is as intuitive as it could be, and some tasks require more clicks and investigation than I'd expect. It feels like a tool built for experienced analysts rather than something that's easy to use right away.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps solve the problem of having security information scattered across different tools. Instead of manually checking multiple alerts and trying to figure out whether they're related, it correlates activity into a single incident. That saves me time, reduces alert fatigue, and helps me investigate threats more efficiently. As a result, I can respond to potential security incidents faster and spend more time focusing on real threats instead of sorting through false positives.

  ### 13. Highly Effective, Intuitive, but Pricey Security Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Abdiel I. | Food Server, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 09, 2026

**What do you like best about Cortex XDR?**

I thought Cortex XDR was a pretty good service. It was very useful and intuitive to use. I found it easy to set up, and it provided good security, giving peace of mind. The AI tools are very good, contributing to its intuitive nature.

**What do you dislike about Cortex XDR?**

I think just, maybe the pricing, is a bit expensive and they may have an option for simpler use and then an option for advanced security usage. So that, someone that's not familiar with the tools can take advantage of the features. The AI tools are very good. So maybe just update that a little bit more so that it's even more intuitive, I would recommend.

**What problems is Cortex XDR solving and how is that benefiting you?**

I recommended Cortex XDR for enhancing front-end security in our startup, providing peace of mind. It's easy to use and very intuitive, making it straightforward even for newcomers.

  ### 14. XDR multidomain with great performance and reliability

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jesús C. | Head of Security Operations, Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

Multidomain correlation of threats, being genuinely useful. XDR correlates network events, identity, email, etc., clearly showing the root cause behind the alert or incident. The product's performance is very good in terms of endpoint, although, it is true, the investment is higher compared to competitors. The support is useful and the AI roadmap they apply is on par with a leader in cybersecurity.

**What do you dislike about Cortex XDR?**

The justification for the investment, as I said, the cost is higher than competitors, making it difficult to justify the cost to invest in the product year after year.

**What problems is Cortex XDR solving and how is that benefiting you?**

Complete control of the endpoint, additional visibility and monitoring, creating a security monitoring service based on the events generated by the console.

  ### 15. Streamlined Security and Enhanced Visibility with Cortex XDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** David Moisés R. | Business Process Consultant, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 01, 2026

**What do you like best about Cortex XDR?**

I really like the visual incident timeline in Cortex XDR. It saves us hours of guesswork, particularly when an automated script triggers an alert. We no longer have to dig through raw log files to piece together what happened, which was a major issue for us before.

**What do you dislike about Cortex XDR?**

The biggest hurdle is the learning curve for custom threat hunting. They could really improve this by adding a visual, drag and drop query builder instead of forcing the user to write raw code from scratch. Also, configuring the security policies took some work.

**What problems is Cortex XDR solving and how is that benefiting you?**

We use Cortex XDR to protect our servers and workstations, improving threat visibility and integration. It addresses alert fatigue and speeds up investigations by reducing guesswork, offering a visual incident timeline that saves us hours by eliminating the need to sift through raw logs.

  ### 16. AI Integrations and Training That Empower Security Operations Visibility

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Enterprise (> 1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

AI intergrations, modern tech transformation and retunr on inveastment with great training aspects. Overall it is a platformt that helps security operaitons and fully empowers visibilty over the nextwok.

**What do you dislike about Cortex XDR?**

The only thing I could think of is that unforunatley I have been seeing more vulnerabilties and CVE repoerts from Palo Alto lately which has me a little concnered about teh backdoors. and third-party upstrema down stream attack surface.

**What problems is Cortex XDR solving and how is that benefiting you?**

The gap it is covereing is attck surface management, visibilty, and use of AI to monitor behavioral based tracking of user, devices, and other IoT devices in daily operations. The Ui/UX is a standard feel so it is not too hard to learn. Also the intergrations with APIs intergrations are good as well.

  ### 17. Robust Detection and Seamless Integration, Steep Pricing

**Rating:** 3.5/5.0 stars

**Reviewed by:** Silvia M. | CISO As a Service, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I really like how Cortex XDR not only detects malicious events but also stops them and prevents harm to devices. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches the alerts, which is valuable to me. Additionally, I appreciate that the transition to Cortex XDR wasn't disruptive for end users since it can coexist with other software, making the change smoother.

**What do you dislike about Cortex XDR?**

I find its pricing per licensing a bit of a downside, and sometimes the learning curve to use Cortex XDR can be a challenge.

**What problems is Cortex XDR solving and how is that benefiting you?**

I find Cortex XDR detects and stops malicious events, protecting my devices from harm. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches my alerts.

  ### 18. Top-Tier Threat Detection with Room for Customization

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

I primarily use Cortex XDR for its accurate threat detection, centralized visibility, and incident investigation capabilities. It helps us focus on real threats by reducing false positives and gives us a complete view of endpoint activity, making investigation faster and response more efficient. I also like the detailed investigation timeline and its integration with other security tools, which makes it easier to analyze incidents and understand the scope of attacks. Additionally, the initial setup was relatively easy, with straightforward agent deployment and helpful documentation. Once everything was configured, the platform was easy to manage.

**What do you dislike about Cortex XDR?**

I think Cortex XDR could improve by making alert management and reporting more customizable. There is also a learning curve for some of the advanced investigation features, but once you are familiar with the platform, it's very effective. More customizable alerts and dashboards would help us focus on the most important security events and generate reports more efficiently. A more intuitive interface for advanced features would also help new users get up to speed faster and improve day-to-day productivity.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR for endpoint detection, threat monitoring, and reducing false positives. It provides centralized visibility, speeds up incident response, and integrates with other security tools, making threat detection and investigation more efficient.

  ### 19. Powerful Threat Detection with a Learning Curve

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Alternative Dispute Resolution | Enterprise (> 1000 emp.)

**Reviewed Date:** July 28, 2026

**What do you like best about Cortex XDR?**

I like Cortex XDR's centralized visibility into endpoint activity and its quality of behavioral detections. The incident timeline is great because it makes it easy to understand how an attack unfolded, speeding up investigations. I also appreciate the ability to isolate compromised endpoints remotely and perform live response actions without needing physical access to the device. The platform provides a balance between strong detection capabilities and an intuitive interface, which makes it easier for our security team to investigate and respond efficiently.

**What do you dislike about Cortex XDR?**

While Cortex XDR is a powerful platform, there are a few areas that could be improved. The interface can feel overwhelming for new users, and some advanced features have a steep learning curve. Creating custom detection rules and XQL queries often requires specialized knowledge. Additionally, investigations can sometimes be slowed by the amount of data presented, and it would be helpful if reporting and dashboard customization were more flexible. Better documentation and more built-in guided workflows for common security tasks would also improve the overall user experience.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR for endpoint protection, helping detect threats, improve visibility, and streamline incident response by reducing alert fatigue through correlating events. It enhances threat detection, speeds up investigations, and isolates compromised devices quickly for better security management.

  ### 20. Fast, Seamless Region Connections with No Noticeable Latency

**Rating:** 4.0/5.0 stars

**Reviewed by:** Joe F. | UNICEF National Internship Program, Enterprise (> 1000 emp.)

**Reviewed Date:** July 17, 2026

**What do you like best about Cortex XDR?**

So far I don't recognize any latency issues even while it was running in the background. Also it can be connected to different regions quite fast and seamless.

**What do you dislike about Cortex XDR?**

Sometimes it can occupy some memory when my computer is running on a lot of ai processes that are resource hungry. Sometimes region switching fail too

**What problems is Cortex XDR solving and how is that benefiting you?**

I feel more secured to use internet or access want websites because cortex xdr save me the trouble from manually checking website security one by one.

  ### 21. Impressive AI Threat Detection with Clear, End-to-End Attack Stories

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Cortex XDR?**

Honestly, it's the way it just gets the big picture. Instead of drowning you in a million random alerts, it stitches everything together from endpoints, network, cloud, and identity stuff into these clear attack stories. The AI and behavioral analytics are seriously impressive - it catches sneaky threats that other tools miss, and the root cause analysis saves me so much time during investigations.

**What do you dislike about Cortex XDR?**

he biggest thing that still bugs me is the learning curve and how complex it can feel at first. The interface is packed with features, which is great once you know it, but it can overwhelm you in the beginning and takes real time to tune properly. Pricing is another sore spot - it's definitely on the expensive side, especially with the extra costs for data lake storage and the licensing complexity.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR effectively addresses several key challenges in modern security operations, primarily the fragmentation of security tools and the overwhelming volume of alerts from siloed systems. By ingesting and correlating data from endpoints, networks, cloud environments, identity sources, and third-party tools, it provides unified visibility and reduces the noise that typically burdens SOC teams. The platform's AI-driven behavioral analytics and automated root cause analysis help us detect sophisticated, multi-stage attacks that traditional signature-based solutions often miss. This has significantly improved our mean time to detect (MTTD) and respond (MTTR). As a result, our team spends less time chasing false positives and more time on actual threats, leading to greater efficiency, reduced operational overhead, and stronger overall security posture. For our organization, it has delivered measurable improvements in incident response speed and threat prevention.

  ### 22. XDR’s Smart Alert Grouping and Automation Cut SOC Triage Time

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

The grouping engine is the standout feature. XDR automatically correlates related alerts into unified incidents, so instead of triaging 30 individual alerts you're reviewing 3-4 cases with full context already stitched together — endpoint telemetry, network activity, and identity signals all in one view.

The causality chain visualization makes it straightforward to trace process trees and understand attack flow without manually pivoting between tools. You can see parent-child process relationships, file writes, network connections, and registry changes in a single timeline.

Automation profiles let you define response actions (isolate host, kill process, quarantine file) that trigger automatically on high-confidence detections, which means analysts only handle the cases that genuinely need human judgment. This significantly reduces alert fatigue and manual toil for the SOC — routine malware detections get contained without anyone touching them.

The interface is clean and the query language (XQL) gives you direct access to raw telemetry when you need to dig deeper than the pre-built views offer.

**What do you dislike about Cortex XDR?**

No out of box fleet sweeping feature. Threat intel integration is weak and lacks actionable context. The agentic assistant (Cortex AI) still has rough edges and provides limited practical value during real investigations.

**What problems is Cortex XDR solving and how is that benefiting you?**

Endpoint security and detection — gives the SOC team deep visibility into endpoint behaviour for alert investigation. The built-in SOAR platform (XSOAR integration) streamlines response workflows, reducing mean time to respond and allowing analysts to focus on genuine threats rather than manual triage steps.

  ### 23. Comprehensive Security, Some Complexity

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I use Cortex XDR to block malware, detect hidden attacks, and investigate security threats. The best part about it is how it automatically links data points from different IT sources into a single timeline, which eliminates the need for analysts to manually gather pieces from firewalls, emails, endpoints, or cloud logs. I also find the root cause analysis, native integration, smart response, incident grouping, and cross-data analytics to work especially well.

**What do you dislike about Cortex XDR?**

I find the policy management capability very complex, even though it's a market-leading security platform. There's rigid alert suppression, feature gaps across OS, high resource consumption, and a steep learning curve. Additionally, while cloud provisioning was easy, I found the agent rollout quite complex.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to block malware, detect hidden attacks, and investigate security threats. It solves alert fatigue, slow investigations, and unknown malware issues. The platform links data into a single timeline, making it easier to see the full attack picture.

  ### 24. Smart Score and Identity Threat Detection Make Prioritizing Threats Easy

**Rating:** 4.5/5.0 stars

**Reviewed by:** yikhong h. | Senior Network Security Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

Smart Score and it can automate incident scoring that helps analysts prioritize the most critical threats first.
Identity Threat Detection and it can correlate user behavior with endpoint activity to spot compromised credentials.

**What do you dislike about Cortex XDR?**

Cortex XDR by Palo Alto Networks is primarily integrated within the Palo Alto ecosystem. As a result, there are significant functionality gaps between the Windows, Linux, and Mac versions. Additionally, the cost of Cortex XDR is comparatively high.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR improves endpoint visibility by providing real-time insight into endpoint activity, including processes, network connections, registry changes, and file operations. This helps support effective threat hunting and forensic investigations, and gives organizations clearer visibility into their overall endpoint security posture.

  ### 25. Automatic correlation and causal chain of Cortex XDR facilitate root cause analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 20, 2026

**What do you like best about Cortex XDR?**

The main advantage of Cortex XDR lies in its ability to automatically aggregate and correlate data from multiple vectors (such as endpoints, network, and identities). The Data Stitching functionality and the presentation of the causal chain significantly simplify root cause analysis, allowing precise identification of the entry vector and the behavior of complex routines, such as Living off the Land attacks.

**What do you dislike about Cortex XDR?**

The main drawbacks do not lie in the detection capability, but rather in the technical complexity of XQL, the financial investment, and the effort required in the initial phase of agent optimization to avoid performance impact or false positives.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR fundamentally resolves the fragmentation of security visibility and the slowness in investigations. Before its adoption, incident analysis required the manual cross-referencing of data between different platforms (EDR, firewalls, identities, and cloud). The tool eliminates this separation through Data Stitching, correlating telemetry into a single incident and significantly reducing alert fatigue. Additionally, it facilitates the identification of the root cause by visually presenting the causal tree of processes and simplifies the detection of evasive threats that use legitimate system tools (Living off the Land).

  ### 26. Powerful Threat Visibility, but a Steep Learning Curve and Tuning Needed

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Banking | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 09, 2026

**What do you like best about Cortex XDR?**

What I like best about Cortex XDR is how it brings data from endpoints, network activity, and other security sources into one place. It makes investigating threats much faster because you can see the full picture instead of jumping between different tools. The automation and AI-driven analytics also help reduce alert fatigue, so I can focus on the incidents that actually matter

**What do you dislike about Cortex XDR?**

What I dislike about Cortex XDR is that it can have a steep learning curve, especially when you're first getting used to the interface and investigation workflows. Some advanced features take time to master, and the amount of data can feel overwhelming. It can also generate noisy alerts if it's not properly tuned, so regular policy and detection adjustments are important

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR benefits me by giving me a single place to monitor and investigate security events. It helps me identify threats faster, reduces the number of false positives I have to deal with, and automates parts of the investigation process. That means I spend less time on repetitive tasks and more time responding to real security incidents

  ### 27. Excellent Threat Detection and Seamless Integration with Palo Alto Networks Tools

**Rating:** 5.0/5.0 stars

**Reviewed by:** Tej D. | Secretary, Telecommunications, Enterprise (> 1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Cortex XDR?**

Excellent detection score for the latest attack. Can be easily integrated into the latest tools like Palo Alto Networks Next-Generation Firewalls (NGFW) and Prisma. can be accomulate and stitch the multi-source data. Flowlss tools to work.

**What do you dislike about Cortex XDR?**

Needs to take complex knowledge to operate. Takes a bit more resources than needed due to its legacy system. Initial implementation needs complex fine-tuning of rules and configuration. Complex Learning curve

**What problems is Cortex XDR solving and how is that benefiting you?**

Transforming chaotic security logs into an automated, highly accurate defense system. Accelerates Incident Response. Complete Network Visibility. Log Monitoring. Log Analysis and helps in decision support system.

  ### 28. Lightweight agent and a Modern Console with Strong Vendor Support

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Enterprise (> 1000 emp.)

**Reviewed Date:** April 02, 2026

**What do you like best about Cortex XDR?**

Real time detection and prevention, lightweight agent as well as agentless solution available, managed through a single modern cloud-based console. Easy integration with data sources such as Amazon S3, Microsoft Teams, Email messaging, Google Cloud, and more. The Cortex XDR console offers fast and clean user interface, and it opens fast and performs very well. Cost may be high depending on the features selected and the number of devices, but in our deployment it was good investment, considering the level of protection we received and the quality of the support from the vendor. The built-in AI intelligence is an added value.

**What do you dislike about Cortex XDR?**

Licensing can be confusing, especially with the cloud protection, and may add cost quickly. New releases and the added new features require constant learning.

**What problems is Cortex XDR solving and how is that benefiting you?**

Replacing traditional anti-virus product in our environment with Cortex XDR improved drastically the level of protection of our systems and the security of our network. Being a very large company, we were able to acquire the XDR Pro licenses for all our endpoints and benefit for the advances behavioral protection, telemetry and reporting. Our SOC team can quickly identify and stop active threats and keep the environment clean.

  ### 29. Cortex XDR Delivers Powerful Endpoint Control and Extended Detection

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The cortex XDR is not a typical EDR solution it has extended detection and response capabilities which gives full control on the endpoints integrated with it. From isolation to shell control all can be done through cortex XDR.

**What do you dislike about Cortex XDR?**

1- The GUI of the cortex XDR solution is not user friendly.
2- The solution is very expensive for small and mid-size organizations.
3- The deployment of the solution is more complex than normal XDR solution.

**What problems is Cortex XDR solving and how is that benefiting you?**

1- It is giving management interface to maintain and manage all of your assets which is integrated with Cortex XDR.
2- The have both the capability of agent and agentless integration for devices which does not support agent installation.
3- The endpoints can be management by shell control from the XDR solution without interrupting user work.

  ### 30. Effective Endpoint Monitoring, Smooth Workflow

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Hospitality | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 29, 2026

**What do you like best about Cortex XDR?**

I found Cortex XDR effective for checking and reviewing security alerts. I really like how it combines activity, network, and user actions all together, which makes investigating any intention super smooth. It's great for process activity and network connections, helping me review security alerts much faster since all related steps and activity are in one place. I totally recommend it.

**What do you dislike about Cortex XDR?**

As i said i didn't use it much to judge, just for a while and it was perfect along that.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR for endpoint monitoring and basic threat investigation. It effectively checks and reviews security alerts by combining process activity, network connections, and user actions, making it easier to investigate issues and reducing the need to switch between multiple tools.

  ### 31. Cortex XDR Delivers Unified Threat Visibility and Faster Incident Response

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sushriya M. | Advisory Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** March 13, 2026

**What do you like best about Cortex XDR?**

Cortex XDR helps solve the problem of detecting and responding to security threats across endpoints, network and cloud in one platform. It benefits me by giving better visibility into attacks and helping investigate and respond to incidents faster with fewer alerts to analyze. Integration with SIEM solutions is effective. Easy to use on a daily basis. Customer support is effective.

**What do you dislike about Cortex XDR?**

It can be expensive and some advanced features require additional configuration or licensing to use fully.

**What problems is Cortex XDR solving and how is that benefiting you?**

The grouping of alerts and the ability to provide a detailed yet concise overview of each alert including implementation, artifacts, impacts, and the timeline make it much easier to understand what’s happening.

  ### 32. Centralized Palo Alto Logging That Keeps Everything Easy to Review

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ernesto M. | IT Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 07, 2026

**What do you like best about Cortex XDR?**

It provides a centralized logging system for all of my Palo Alto logs, keeping everything in one place and easier to review.

**What do you dislike about Cortex XDR?**

It requires a license, and some parts can be difficult to learn if you don’t follow the proper guidance. I think this is because Palo Alto has changed names a few times now.

**What problems is Cortex XDR solving and how is that benefiting you?**

It’s helpful to have centralized log ingestion and monitoring in one place.

  ### 33. Advanced Detection and Extended Telemetry

**Rating:** 4.0/5.0 stars

**Reviewed by:** Christian Noel C. | Jefe Regional de Inteligencia de Ciberseguridad | CIC |, Enterprise (> 1000 emp.)

**Reviewed Date:** April 28, 2026

**What do you like best about Cortex XDR?**

I like the analysis and anomaly detection capabilities of Cortex XDR, as it supports my Blue Team in detecting potential cybersecurity incidents on a daily basis. I also highly value the extended telemetry capability that provides us with extensive details of all alerts and the validations that Cortex XDR has already performed on its own.

**What do you dislike about Cortex XDR?**

The control of applications

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to protect endpoints and servers, it is compatible with Ubuntu and Windows legacy operating systems. It helps us with the detection of cybersecurity incidents and its extended telemetry provides us with complete details and automatic validations.

  ### 34. Advanced Analytics and Root-Cause Clarity for Faster Threat Detection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 18, 2026

**What do you like best about Cortex XDR?**

Advanced analytics and root-cause analysis. It displays the exact chain of events during an attack, points out precisely how a threat entered the network, and uses machine learning to spot abnormal user or device behavior.

**What do you dislike about Cortex XDR?**

High cost and licensing complexity. It costs significantly more than entry-level EDR solutions and often requires additional licenses to access advanced features such as forensics or identity analytics.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR automatically stitches together telemetry from endpoints, network firewalls, cloud workloads, and identity providers, giving us total visibility. As a result, analysts no longer have to manually piece together logs from different consoles just to understand what happened.

  ### 35. Strong Threat Protection, but Too Many Emails and a Less User-Friendly Experience

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Hospitality | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Cortex XDR?**

It is an endpoint detection and response product. It’s used by your IT department to protect you from threats and detect malicious behavior. Which is good

**What do you dislike about Cortex XDR?**

A lot of communication emails and alot of promotional emails which are a bit annoying and the software could be a bit more user friendly than what it is now

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR detects and responds to cyber threats faster by correlating security data, reducing false positives, automating responses, and improving visibility.

  ### 36. Exceptional Threat Detection and Endpoint Protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** anshu Y. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 01, 2025

**What do you like best about Cortex XDR?**

Ability to investigate and remediate security incidents. Cortex XDR protects our endpoints against advanced threats like malware, viruses and ransomware. Cortex XDR is a convenient tool for hunting advanced threats. It is a reliable tool that reduces false positives. Support and integrations with native apps and Broker VM are very simple.

**What do you dislike about Cortex XDR?**

Cortex XDR is a well-suited solution for endpoint protection, hence I don't have any limitations to pinpoint.

**What problems is Cortex XDR solving and how is that benefiting you?**

I am happy to say that Cortex XDR uses the power of AI and Machine Learning to speed up security threat detection and response. Again, Cortex XDR provides bird's-eye visibility into our organization's endpoints. Cortex XDR integrates seamlessly with other security tools, thus improving our security posture.

  ### 37. Unified Threat Detection That Accelerates Investigations

**Rating:** 4.5/5.0 stars

**Reviewed by:** Parth S. | Security Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 10, 2025

**What do you like best about Cortex XDR?**

Its unified detection and response capability that correlates endpoint, network, and cloud telemetry for faster, more accurate threat investigation

**What do you dislike about Cortex XDR?**

Sometimes it feels a bit heavy to manage, and the learning curve can be steeper than expected when tuning policies or customizing detections

**What problems is Cortex XDR solving and how is that benefiting you?**

It pulls together alerts from across endpoints and the network to spot threats sooner, making investigations faster and reducing a lot of manual security noise.

  ### 38. Cortex XDR: Threat Detection made simple

**Rating:** 4.0/5.0 stars

**Reviewed by:** Carlos J. | Threat Detection and Response Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** September 24, 2025

**What do you like best about Cortex XDR?**

I like it's ability to dig into the niche areas of cmd and process trees to identify common used TTPs.

**What do you dislike about Cortex XDR?**

Too many false positives, needs fine tuning or alert fatigue will be a big problem.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex is identifying threats in all the systems layers

  ### 39. Excellent detection and minimal false positives of cortex.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nixon L. | Especialista de ciberseguridad, Enterprise (> 1000 emp.)

**Reviewed Date:** September 30, 2025

**What do you like best about Cortex XDR?**

I highlight its broad scope for detecting potential threats.

**What do you dislike about Cortex XDR?**

The customization it offers usually requires a very manual process.

**What problems is Cortex XDR solving and how is that benefiting you?**

It is offering exceptional protection.

  ### 40. Palo alto Cortex XDR review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Χρηστος . | Junior IT Support, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 13, 2024

**What do you like best about Cortex XDR?**

Easy to setup the endopoint to customers and realtime alerting

**What do you dislike about Cortex XDR?**

Somitimes the alerts arent right. For example cortex thinks tha outlook is a malware

**What problems is Cortex XDR solving and how is that benefiting you?**

You can make the XDR as strticed as you want , so you give different permitions for groups and users

  ### 41. Cortex is technically very sound and good product as per cyber security point of view.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Viral B. | Head IT, Pharmaceuticals, Enterprise (> 1000 emp.)

**Reviewed Date:** January 22, 2024

**What do you like best about Cortex XDR?**

Cortex updates about latest defination as per cyber attacks trends. Also knowlege base documents are very good.

**What do you dislike about Cortex XDR?**

Not user friendly. For ease of use person need to work. Customer support is not good.

**What problems is Cortex XDR solving and how is that benefiting you?**

It help us on secure of assets from cyber attack. Really good product for Cyber Security

  ### 42. Best tool that protects your Computer as a whole

**Rating:** 4.0/5.0 stars

**Reviewed by:** Hasan S. | T24 Technical Consultant, Banking, Enterprise (> 1000 emp.)

**Reviewed Date:** July 06, 2023

**What do you like best about Cortex XDR?**

Cortex XDR is a fantastic utility provided by Palo Alto Networks. It has a vibrant interface and is easy to use. It offers unique features like Anti-Exploit protection along with Anti-Malware protection. The best thing about this software is that while it scans the system, it does not reduce the speed of other tasks. It detects different kinds of bugs like trojan horses and other types of viruses quickly and prompts users to act on those tasks. Overall my experience using this program is very good.

**What do you dislike about Cortex XDR?**

This program is excellent in its unique nature and functionality, except for restricting some core functionalities embedded in Operating System. For example, I installed some software, and it did not allow me to install those on my machine.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helped me in many ways, mainly because it saved me many times from dangerous viruses and trojans. It usually scans my computer as soon as I turn on my machine, and it never slows down my laptop's overall speed or performance. It takes minimal resources to perform its job without impacting other programs to do their jobs.

  ### 43. Best threat protection our school system has ever had.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Shawn O. | Systems Support Specialists, Enterprise (> 1000 emp.)

**Reviewed Date:** September 12, 2023

**What do you like best about Cortex XDR?**

The simplicity of the interface and the managability of the platform.

**What do you dislike about Cortex XDR?**

Cost of product is pretty high for a public school system but well worth the price you pay.

**What problems is Cortex XDR solving and how is that benefiting you?**

It has resolved our threat prevention and detection issues.  We use to use a basic AV platform and we tried several but this has been a game changer for us.

  ### 44. An Effective EDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2023

**What do you like best about Cortex XDR?**

This EDR solution stands out as highly effective in the market, excelling at managing and deploying a large number of endpoints seamlessly. Its versatility extends to supporting various operating systems, making it a convenient choice. The user-friendly interface further enhances its appeal, ensuring ease of use.

**What do you dislike about Cortex XDR?**

The frequency of false positives detected can be improved for better accuracy. Additionally, there is room for enhancement in customer service to address and resolve queries more effectively.

**What problems is Cortex XDR solving and how is that benefiting you?**

It improves business process outcomes by streamlining and optimizing various workflows. It fosters internal and operational efficiencies, leading to increased productivity and cost savings. The advanced data analytics and insights provided by the suite, decision-making processes are enhanced, allowing businesses to make more informed and strategic choices.

  ### 45. Amazing solution for endpoint protection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ahmed A. | Information Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2023

**What do you like best about Cortex XDR?**

It is user friendly solution and cloud based endpoint protection soft. It is the number one in the sector.

**What do you dislike about Cortex XDR?**

About linux protection I fan say that it should be improved

**What problems is Cortex XDR solving and how is that benefiting you?**

We are protecting our endpoints and manage in some cases

  ### 46. Cortex XDR, The All-In-One Solution

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Primary/Secondary Education | Enterprise (> 1000 emp.)

**Reviewed Date:** June 30, 2022

**What do you like best about Cortex XDR?**

Cortex XDR is highly sophisticated software that's backed by Artificial Intelligence and Machine Learning. I've appreciated how it only pushes alerts that are truly important.

**What do you dislike about Cortex XDR?**

There is a noticeable performance impact on lower-end systems where the Cortex XDR agent is installed. I'd also like the quick launcher to have an option to open the endpoint in the All Endpoints section.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR gives full coverage against all categories of malicious threats. It's been really nice being able to trust Cortex XDR to take care of our endpoints. Cortex XDR is super easy to use compare to TRAPS.

  ### 47. Cortex XDR is a great new solution for endpoint protection

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 22, 2022

**What do you like best about Cortex XDR?**

Cortex has a great interface - easy to navigate, nice design, very functional

**What do you dislike about Cortex XDR?**

It was a tad difficult to figure out where to configure initial setup - but once I located that, was simple

**What problems is Cortex XDR solving and how is that benefiting you?**

New type of antivirus/antimalware detection - simple installation, small footprint, so far I am liking it

  ### 48. Best tool to reduce the work load from Secops

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 01, 2022

**What do you like best about Cortex XDR?**

Overall experience with this product is really good, This tool reduces the load from the SecOps team with the help of incident Detection, Alerts and Analysed report.

**What do you dislike about Cortex XDR?**

Nothing, Working perfectly for our organization

**What problems is Cortex XDR solving and how is that benefiting you?**

The mostly liked the about this tool unified Incident management and its detecting the incidents from the sensors and managing the cross platform detection the incidents.

  ### 49. Works and integrates well with Palo Alto NGFW

**Rating:** 4.5/5.0 stars

**Reviewed by:** Mike P. | Network Services Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 11, 2021

**What do you like best about Cortex XDR?**

Reporting/inventory of systems and being able to identify agent levels and operating system.  The ability to triage/investigate from the mainpage is great.  The continual development is nice as we've seen steady improvement from the Traps days.

**What do you dislike about Cortex XDR?**

licensing has been a bit all over the place and hopefully is simplified now.  Would love to see it integrate more with other security products and not just Palo Alto.  Bringing some extra flexibility would be nice.

**What problems is Cortex XDR solving and how is that benefiting you?**

Being able to identify machines that don't have coverage has always been the problem.  We have increased visibility now that we've never had before.  Ease of deployment and upgrades of agents is also fairly straightforward.

  ### 50. Cortext XDR - Good AV

**Rating:** 4.5/5.0 stars

**Reviewed by:** Ashley M. | System Administrator, Enterprise (> 1000 emp.)

**Reviewed Date:** January 13, 2022

**What do you like best about Cortex XDR?**

Centralised management interface and stability of client

**What do you dislike about Cortex XDR?**

Agent was unstable once or twice on inital update

**What problems is Cortex XDR solving and how is that benefiting you?**

Early protection from virus threats


## Cortex XDR Discussions
  - [What is Cortex XDR?](https://www.g2.com/discussions/what-is-cortex-xdr) - 1 comment

- [View Cortex XDR pricing details and edition comparison](https://www.g2.com/products/palo-alto-networks-cortex-xdr/reviews?section=pricing&secure%5Bexpires_at%5D=2026-08-04+13%3A06%3A53+-0500&secure%5Bsession_id%5D=f213fb77-99fb-4200-bd14-bdefb7882ad0&secure%5Btoken%5D=0df567ab41ce920a63728d41bbd82689da4fd212f1eafd3bfc29306ab0b6fbf9&format=llm_user)
## Cortex XDR Integrations
  - [Amazon Simple Storage Service (S3)](https://www.g2.com/products/amazon-simple-storage-service-s3/reviews)
  - [Google Cloud Storage](https://www.g2.com/products/google-cloud-storage/reviews)
  - [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  - [Google Workspace](https://www.g2.com/products/google-workspace/reviews)
  - [Graylog](https://www.g2.com/products/graylog/reviews)
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  - [Palo Alto Networks Next-Generation Firewalls](https://www.g2.com/products/palo-alto-networks-next-generation-firewalls/reviews)
  - [RadarQ](https://www.g2.com/products/radarq/reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

## Cortex XDR Features
**Administration**
- Compliance
- Web Control
- Application Control
- Asset Management
- Device Control

**Analysis**
- Incident Reporting
- Network Visibility
- Metadata Enrichment
- Metadata Management

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- System Isolation
- Firewall
- Endpoint Intelligence
- Malware Detection

**Response**
- Incident Alerts
- Response Orchestration
- Response Automation

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility

**Security**
- Data Security
- Data loss Prevention
- Security Auditing

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Analysis**
- Automated Remediation
- Incident Reports
- Behavioral Analysis

**Detection**
- Multi-Network Monitoring
- Asset Discovery
- Anomaly Detection

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Identity**
- SSO
- Governance
- User Analytics

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Detection and Response (CDR)**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Services - Network Detection and Response (NDR)**
- Managed Services

**Services - Extended Detection and Response (XDR)**
- Managed Services

**Services - Cloud Detection and Response (CDR) **
- Managed Services

## Top Cortex XDR Alternatives
  - [Sophos Endpoint](https://www.g2.com/products/sophos-endpoint/reviews) - 4.7/5.0 (794 reviews)
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (415 reviews)
  - [ESET PROTECT](https://www.g2.com/products/eset-protect/reviews) - 4.6/5.0 (963 reviews)

