---
title: Cortex XDR Reviews
meta_title: 'Cortex XDR Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 85 reviews by the users' company size, role or industry to
  find out how Cortex XDR works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 85
  scale: '5'
date_modified: '2026-08-14'
parent_category:
  name: Cloud Security
  url: https://www.g2.com/categories/cloud-security
---


# Cortex XDR Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Extended Detection and Response (XDR) Platforms](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 85
## About Cortex XDR
Cortex XDR is the industry’s first extended detection and response platform that stops modern attacks by integrating data from any source. With Cortex XDR, you can harness the power of AI, analytics and rich data to detect stealthy threats. Your SOC team can cut through the noise and focus on what matters most with intelligent alert grouping and incident scoring. Cross-data insights accelerate investigations, so you can streamline incident response and recovery. Cortex XDR delivers peace of mind with best-in-class endpoint protection that achieved the highest combined protection and detection scores in the MITRE ATT&amp;CK® round 3 evaluation. The Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic protection to secure what’s next.



## Cortex XDR Pros & Cons
**What users like:**

- Users value the **important alert notifications** from Cortex XDR, which enhance security without overwhelming them. (2 reviews)
- Users appreciate the **simplicity and manageability** of Cortex XDR, finding it easy to navigate and utilize effectively. (2 reviews)
- Users love the **unique features** of Cortex XDR, especially its effective threat detection without compromising system speed. (2 reviews)
- Users praise the **unified detection and response capability** of Cortex XDR, enhancing threat investigation efficiency and accuracy. (2 reviews)
- Users value the **unified detection and response capability** of Cortex XDR for swift and precise threat investigations. (2 reviews)
- AI (1 reviews)
- AI Technology (1 reviews)
- Alerting (1 reviews)
- Alerts (1 reviews)
- Users appreciate the **effective antivirus protection** of Cortex XDR, as it quickly detects and handles various threats. (1 reviews)

**What users dislike:**

- Users find **limited features** in Cortex XDR, with restrictions affecting core OS functionalities and usability issues on lower-end systems. (2 reviews)
- Users experience a **noticeable performance impact** on lower-end systems with the Cortex XDR agent installed. (1 reviews)
- Users face **compatibility issues** with Cortex XDR, restricting core functionalities and software installations on their machines. (1 reviews)
- Users find the **system complexity** challenging, often struggling with management and a steep learning curve. (1 reviews)
- Users find the **complex management** of Cortex XDR challenging due to its steep learning curve and customization difficulties. (1 reviews)
- Users find the **difficult learning curve** challenging, especially when managing policies and customizing detections in Cortex XDR. (1 reviews)
- Users find the Cortex XDR to be **expensive** for public school systems, but value its worth despite the cost. (1 reviews)
- Users note the **restrictive core functionalities** of Cortex XDR, limiting certain installations and affecting usability. (1 reviews)
- High Resource Usage (1 reviews)
- Users face **installation difficulties** with Cortex XDR, as it restricts some core OS functionalities during setup. (1 reviews)

## Cortex XDR Reviews
  ### 1. Comprehensive Threat Detection with Efficient Response

**Rating:** 4.0/5.0 stars

**Reviewed by:** Hunny B. | Network Engineer, Computer & Network Security, Enterprise (> 1000 emp.)

**Reviewed Date:** August 03, 2026

**What do you like best about Cortex XDR?**

I like Cortex XDR's ability to correlate data from multiple sources into a single instrument, which helps review hundreds of individual alerts by providing a complete attack timeline. This feature makes it easier for security teams to investigate and respond much faster. Its automated response capabilities, like isolating compromised endpoints and stopping malicious processes, are impressive because they help reduce the impact of an attack. Another aspect I appreciate is its centralized management, which allows security teams to monitor endpoints, investigate incidents, and respond from a single console, improving visibility and reducing investigation time. I also value the detailed attack timeline feature for simplifying root cause analysis.

**What do you dislike about Cortex XDR?**

I haven't used cortex XDR in a prodcution environment, so i can't comment on its limitations from personla experience. However, based on my research and industry discussions, one are that can require attention is the initial tunning of detection policies to minimize false positives and ensure are meaningful.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps us detect and respond to advanced cyber threats missed by traditional antivirus, correlating data into a single incident to investigate and respond quicker. It offers centralized management and automated responses, reducing attack impact and improving visibility.

  ### 2. Robust Threat Detection, But a Steep Learning Curve

**Rating:** 4.0/5.0 stars

**Reviewed by:** Dev S. | Network Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

What I like most about Cortex XDR is how it connects the dots between tiny, suspicious events and the bigger attack story they're part of. That correlation view saves a lot of guesswork, and the behavioral detections tend to catch weird stuff early, even when there's no clear signature. It just feels like it gives us clarity when things are tried to state.

**What do you dislike about Cortex XDR?**

I find the interface feels a little dense, with too many panels and options at once. As a new analyst, I feel overwhelmed until I get used to it. Also, it takes me time to get the alert tuning right because the alerts can be a bit noisy out of the box until I fine-tune the policy.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helps us spot hidden threats that normal antivirus tools miss, like ransomware and fileless attacks. It correlates endpoint and network data, cutting investigation time and providing a clear path to contain devices and respond quickly before damage spreads.

  ### 3. Causality Engine Delivers Fast, End-to-End Attack Visibility

**Rating:** 4.0/5.0 stars

**Reviewed by:** Amaan M. | Soc Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The endpoint agent and the causality engine really stand out for us. We came from a traditional EDR that generated a flood of separate alerts, so XDR’s ability to tie process, network, and user activity together into a single causal chain has been a big improvement. It lets analysts see the full story of an attack instead of piecing together fragments. Root-cause analysis that used to take an hour of pivoting now takes just minutes.

**What do you dislike about Cortex XDR?**

The management console has a steep learning curve. There are many nested menus, and finding specific settings or policies isn’t always intuitive. New analysts need real ramp-up time before they can be productive in the UI. Some workflows also require jumping between different sections of the console more than they should, which slows things down. Reporting is another weak spot. The built-in reports cover the basics, but anything customized for executive or compliance audiences typically means exporting data and building it elsewhere.

**What problems is Cortex XDR solving and how is that benefiting you?**

The biggest value XDR brings is unified visibility across endpoints, networks, and identities, which eliminates fragmented alerts and the need for manual correlation. Its causality engine automatically links related events into a single incident, giving analysts a clear view of the full attack chain rather than a set of isolated alerts. This can significantly reduce investigation time and support faster triage and containment. In parallel, the unified agent brings prevention, EDR, and host controls together in one solution, helping reduce tool sprawl, endpoint overhead, and day-to-day operational complexity. Overall, the result is better analyst efficiency, stronger security operations, and lower management overhead.

  ### 4. Strong Correlation and Investigation Depth for SOC-Scale Threat Hunting

**Rating:** 4.0/5.0 stars

**Reviewed by:** Alessandro D. | Technical Leader, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

Cortex XDR stands out in day-to-day SOC operations for how effectively it correlates endpoint, network, and cloud telemetry into a single investigative view. As a Technical Lead managing a team of five analysts, I find the incident timeline and causality-chain visualization especially valuable for threat hunting and incident response—it significantly reduces the time needed to reconstruct an attack path versus piecing together logs across siloed tools. The behavioral analytics engine is also strong at detecting living-off-the-land techniques and lateral movement that signature-based tools often miss. Integration with the broader Cortex ecosystem (especially XSOAR for orchestration) further helps by enabling automation of repetitive triage steps, which is particularly important when maintaining H24 on-call coverage.

**What do you dislike about Cortex XDR?**

The learning curve to fully master the platform is steeper than with some competing EDR/XDR solutions, especially when it comes to fine-tuning detection rules to cut down on noise without sacrificing coverage. New analysts on the team need meaningful ramp-up time before they’re fully productive. Licensing and add-on module costs can also add up quickly if you want full XDR capability (network, cloud, identity) rather than endpoint-only coverage. Occasionally, the alert-correlation logic feels opaque, which makes it harder to explain in post-incident reporting why certain events were grouped together.

**What problems is Cortex XDR solving and how is that benefiting you?**

It’s a core part of our detection and response stack, helping us reduce mean time to detect and respond to incidents by consolidating multiple data sources that analysts would otherwise have to hunt through manually. It’s especially useful for correlating phishing-driven incidents with subsequent endpoint activity, and it also supports our escalation workflows during the 24/7 on-call rotation.

  ### 5. Streamlined Security and Enhanced Visibility with Cortex XDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** David Moisés R. | Business Process Consultant, Computer Software, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 01, 2026

**What do you like best about Cortex XDR?**

I really like the visual incident timeline in Cortex XDR. It saves us hours of guesswork, particularly when an automated script triggers an alert. We no longer have to dig through raw log files to piece together what happened, which was a major issue for us before.

**What do you dislike about Cortex XDR?**

The biggest hurdle is the learning curve for custom threat hunting. They could really improve this by adding a visual, drag and drop query builder instead of forcing the user to write raw code from scratch. Also, configuring the security policies took some work.

**What problems is Cortex XDR solving and how is that benefiting you?**

We use Cortex XDR to protect our servers and workstations, improving threat visibility and integration. It addresses alert fatigue and speeds up investigations by reducing guesswork, offering a visual incident timeline that saves us hours by eliminating the need to sift through raw logs.

  ### 6. Robust Detection and Seamless Integration, Steep Pricing

**Rating:** 3.5/5.0 stars

**Reviewed by:** Silvia M. | CISO As a Service, Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I really like how Cortex XDR not only detects malicious events but also stops them and prevents harm to devices. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches the alerts, which is valuable to me. Additionally, I appreciate that the transition to Cortex XDR wasn't disruptive for end users since it can coexist with other software, making the change smoother.

**What do you dislike about Cortex XDR?**

I find its pricing per licensing a bit of a downside, and sometimes the learning curve to use Cortex XDR can be a challenge.

**What problems is Cortex XDR solving and how is that benefiting you?**

I find Cortex XDR detects and stops malicious events, protecting my devices from harm. Its integration with other Palo Alto software, like SOAR and next-gen firewall, enriches my alerts.

  ### 7. Fast, Seamless Region Connections with No Noticeable Latency

**Rating:** 4.0/5.0 stars

**Reviewed by:** Joe F. | UNICEF National Internship Program, Enterprise (> 1000 emp.)

**Reviewed Date:** July 17, 2026

**What do you like best about Cortex XDR?**

So far I don't recognize any latency issues even while it was running in the background. Also it can be connected to different regions quite fast and seamless.

**What do you dislike about Cortex XDR?**

Sometimes it can occupy some memory when my computer is running on a lot of ai processes that are resource hungry. Sometimes region switching fail too

**What problems is Cortex XDR solving and how is that benefiting you?**

I feel more secured to use internet or access want websites because cortex xdr save me the trouble from manually checking website security one by one.

  ### 8. Impressive AI Threat Detection with Clear, End-to-End Attack Stories

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Oil & Energy | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 27, 2026

**What do you like best about Cortex XDR?**

Honestly, it's the way it just gets the big picture. Instead of drowning you in a million random alerts, it stitches everything together from endpoints, network, cloud, and identity stuff into these clear attack stories. The AI and behavioral analytics are seriously impressive - it catches sneaky threats that other tools miss, and the root cause analysis saves me so much time during investigations.

**What do you dislike about Cortex XDR?**

he biggest thing that still bugs me is the learning curve and how complex it can feel at first. The interface is packed with features, which is great once you know it, but it can overwhelm you in the beginning and takes real time to tune properly. Pricing is another sore spot - it's definitely on the expensive side, especially with the extra costs for data lake storage and the licensing complexity.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR effectively addresses several key challenges in modern security operations, primarily the fragmentation of security tools and the overwhelming volume of alerts from siloed systems. By ingesting and correlating data from endpoints, networks, cloud environments, identity sources, and third-party tools, it provides unified visibility and reduces the noise that typically burdens SOC teams. The platform's AI-driven behavioral analytics and automated root cause analysis help us detect sophisticated, multi-stage attacks that traditional signature-based solutions often miss. This has significantly improved our mean time to detect (MTTD) and respond (MTTR). As a result, our team spends less time chasing false positives and more time on actual threats, leading to greater efficiency, reduced operational overhead, and stronger overall security posture. For our organization, it has delivered measurable improvements in incident response speed and threat prevention.

  ### 9. XDR’s Smart Alert Grouping and Automation Cut SOC Triage Time

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

The grouping engine is the standout feature. XDR automatically correlates related alerts into unified incidents, so instead of triaging 30 individual alerts you're reviewing 3-4 cases with full context already stitched together — endpoint telemetry, network activity, and identity signals all in one view.

The causality chain visualization makes it straightforward to trace process trees and understand attack flow without manually pivoting between tools. You can see parent-child process relationships, file writes, network connections, and registry changes in a single timeline.

Automation profiles let you define response actions (isolate host, kill process, quarantine file) that trigger automatically on high-confidence detections, which means analysts only handle the cases that genuinely need human judgment. This significantly reduces alert fatigue and manual toil for the SOC — routine malware detections get contained without anyone touching them.

The interface is clean and the query language (XQL) gives you direct access to raw telemetry when you need to dig deeper than the pre-built views offer.

**What do you dislike about Cortex XDR?**

No out of box fleet sweeping feature. Threat intel integration is weak and lacks actionable context. The agentic assistant (Cortex AI) still has rough edges and provides limited practical value during real investigations.

**What problems is Cortex XDR solving and how is that benefiting you?**

Endpoint security and detection — gives the SOC team deep visibility into endpoint behaviour for alert investigation. The built-in SOAR platform (XSOAR integration) streamlines response workflows, reducing mean time to respond and allowing analysts to focus on genuine threats rather than manual triage steps.

  ### 10. Comprehensive Security, Some Complexity

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 23, 2026

**What do you like best about Cortex XDR?**

I use Cortex XDR to block malware, detect hidden attacks, and investigate security threats. The best part about it is how it automatically links data points from different IT sources into a single timeline, which eliminates the need for analysts to manually gather pieces from firewalls, emails, endpoints, or cloud logs. I also find the root cause analysis, native integration, smart response, incident grouping, and cross-data analytics to work especially well.

**What do you dislike about Cortex XDR?**

I find the policy management capability very complex, even though it's a market-leading security platform. There's rigid alert suppression, feature gaps across OS, high resource consumption, and a steep learning curve. Additionally, while cloud provisioning was easy, I found the agent rollout quite complex.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to block malware, detect hidden attacks, and investigate security threats. It solves alert fatigue, slow investigations, and unknown malware issues. The platform links data into a single timeline, making it easier to see the full attack picture.

  ### 11. Automatic correlation and causal chain of Cortex XDR facilitate root cause analysis

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 20, 2026

**What do you like best about Cortex XDR?**

The main advantage of Cortex XDR lies in its ability to automatically aggregate and correlate data from multiple vectors (such as endpoints, network, and identities). The Data Stitching functionality and the presentation of the causal chain significantly simplify root cause analysis, allowing precise identification of the entry vector and the behavior of complex routines, such as Living off the Land attacks.

**What do you dislike about Cortex XDR?**

The main drawbacks do not lie in the detection capability, but rather in the technical complexity of XQL, the financial investment, and the effort required in the initial phase of agent optimization to avoid performance impact or false positives.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR fundamentally resolves the fragmentation of security visibility and the slowness in investigations. Before its adoption, incident analysis required the manual cross-referencing of data between different platforms (EDR, firewalls, identities, and cloud). The tool eliminates this separation through Data Stitching, correlating telemetry into a single incident and significantly reducing alert fatigue. Additionally, it facilitates the identification of the root cause by visually presenting the causal tree of processes and simplifies the detection of evasive threats that use legitimate system tools (Living off the Land).

  ### 12. Cortex XDR Delivers Powerful Endpoint Control and Extended Detection

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 24, 2026

**What do you like best about Cortex XDR?**

The cortex XDR is not a typical EDR solution it has extended detection and response capabilities which gives full control on the endpoints integrated with it. From isolation to shell control all can be done through cortex XDR.

**What do you dislike about Cortex XDR?**

1- The GUI of the cortex XDR solution is not user friendly.
2- The solution is very expensive for small and mid-size organizations.
3- The deployment of the solution is more complex than normal XDR solution.

**What problems is Cortex XDR solving and how is that benefiting you?**

1- It is giving management interface to maintain and manage all of your assets which is integrated with Cortex XDR.
2- The have both the capability of agent and agentless integration for devices which does not support agent installation.
3- The endpoints can be management by shell control from the XDR solution without interrupting user work.

  ### 13. Effective Endpoint Monitoring, Smooth Workflow

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Hospitality | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 29, 2026

**What do you like best about Cortex XDR?**

I found Cortex XDR effective for checking and reviewing security alerts. I really like how it combines activity, network, and user actions all together, which makes investigating any intention super smooth. It's great for process activity and network connections, helping me review security alerts much faster since all related steps and activity are in one place. I totally recommend it.

**What do you dislike about Cortex XDR?**

As i said i didn't use it much to judge, just for a while and it was perfect along that.

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR for endpoint monitoring and basic threat investigation. It effectively checks and reviews security alerts by combining process activity, network connections, and user actions, making it easier to investigate issues and reducing the need to switch between multiple tools.

  ### 14. Advanced Detection and Extended Telemetry

**Rating:** 4.0/5.0 stars

**Reviewed by:** Christian Noel C. | Jefe Regional de Inteligencia de Ciberseguridad | CIC |, Enterprise (> 1000 emp.)

**Reviewed Date:** April 28, 2026

**What do you like best about Cortex XDR?**

I like the analysis and anomaly detection capabilities of Cortex XDR, as it supports my Blue Team in detecting potential cybersecurity incidents on a daily basis. I also highly value the extended telemetry capability that provides us with extensive details of all alerts and the validations that Cortex XDR has already performed on its own.

**What do you dislike about Cortex XDR?**

The control of applications

**What problems is Cortex XDR solving and how is that benefiting you?**

I use Cortex XDR to protect endpoints and servers, it is compatible with Ubuntu and Windows legacy operating systems. It helps us with the detection of cybersecurity incidents and its extended telemetry provides us with complete details and automatic validations.

  ### 15. Cortex XDR: Threat Detection made simple

**Rating:** 4.0/5.0 stars

**Reviewed by:** Carlos J. | Threat Detection and Response Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** September 24, 2025

**What do you like best about Cortex XDR?**

I like it's ability to dig into the niche areas of cmd and process trees to identify common used TTPs.

**What do you dislike about Cortex XDR?**

Too many false positives, needs fine tuning or alert fatigue will be a big problem.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex is identifying threats in all the systems layers

  ### 16. Palo alto Cortex XDR review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Χρηστος . | Junior IT Support, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 13, 2024

**What do you like best about Cortex XDR?**

Easy to setup the endopoint to customers and realtime alerting

**What do you dislike about Cortex XDR?**

Somitimes the alerts arent right. For example cortex thinks tha outlook is a malware

**What problems is Cortex XDR solving and how is that benefiting you?**

You can make the XDR as strticed as you want , so you give different permitions for groups and users

  ### 17. Cortex is technically very sound and good product as per cyber security point of view.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Viral B. | Head IT, Pharmaceuticals, Enterprise (> 1000 emp.)

**Reviewed Date:** January 22, 2024

**What do you like best about Cortex XDR?**

Cortex updates about latest defination as per cyber attacks trends. Also knowlege base documents are very good.

**What do you dislike about Cortex XDR?**

Not user friendly. For ease of use person need to work. Customer support is not good.

**What problems is Cortex XDR solving and how is that benefiting you?**

It help us on secure of assets from cyber attack. Really good product for Cyber Security

  ### 18. Best tool that protects your Computer as a whole

**Rating:** 4.0/5.0 stars

**Reviewed by:** Hasan S. | T24 Technical Consultant, Banking, Enterprise (> 1000 emp.)

**Reviewed Date:** July 06, 2023

**What do you like best about Cortex XDR?**

Cortex XDR is a fantastic utility provided by Palo Alto Networks. It has a vibrant interface and is easy to use. It offers unique features like Anti-Exploit protection along with Anti-Malware protection. The best thing about this software is that while it scans the system, it does not reduce the speed of other tasks. It detects different kinds of bugs like trojan horses and other types of viruses quickly and prompts users to act on those tasks. Overall my experience using this program is very good.

**What do you dislike about Cortex XDR?**

This program is excellent in its unique nature and functionality, except for restricting some core functionalities embedded in Operating System. For example, I installed some software, and it did not allow me to install those on my machine.

**What problems is Cortex XDR solving and how is that benefiting you?**

Cortex XDR helped me in many ways, mainly because it saved me many times from dangerous viruses and trojans. It usually scans my computer as soon as I turn on my machine, and it never slows down my laptop's overall speed or performance. It takes minimal resources to perform its job without impacting other programs to do their jobs.

  ### 19. An Effective EDR

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Enterprise (> 1000 emp.)

**Reviewed Date:** July 24, 2023

**What do you like best about Cortex XDR?**

This EDR solution stands out as highly effective in the market, excelling at managing and deploying a large number of endpoints seamlessly. Its versatility extends to supporting various operating systems, making it a convenient choice. The user-friendly interface further enhances its appeal, ensuring ease of use.

**What do you dislike about Cortex XDR?**

The frequency of false positives detected can be improved for better accuracy. Additionally, there is room for enhancement in customer service to address and resolve queries more effectively.

**What problems is Cortex XDR solving and how is that benefiting you?**

It improves business process outcomes by streamlining and optimizing various workflows. It fosters internal and operational efficiencies, leading to increased productivity and cost savings. The advanced data analytics and insights provided by the suite, decision-making processes are enhanced, allowing businesses to make more informed and strategic choices.

  ### 20. ELEKS bolsters its security services by partnering with Secdo

**Rating:** 4.0/5.0 stars

**Reviewed by:** Iurii G. | Head of Corporate Security, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** October 30, 2017

**What do you like best about Cortex XDR?**

I’m pleased to introduce the ELEKS new security service portfolio powered by Secdo. Secdo’s preemptive incident response platform allows slashing the incident response time from months to minutes. We are happy to use this solution in-house as well as to recommend it to our customers. This partnership brings a strong security support to our business and allows us to offer improved security services to our clients.

**What do you dislike about Cortex XDR?**

Often we need some additional functionality (flexible reporting for instance), more visibility into agents and their hardening from the solution itself. Anyway, Secdo team is amazingly professional and we have it within days or already in the product roadmap.

**What problems is Cortex XDR solving and how is that benefiting you?**

- ELEKS quickly and cost-effectively introduced new services – prompt incident response, threat-hunting. 
- We are able to perform remote response without impacting business productivity, remote remediation while end-users continue to work.

  ### 21. Reliable software

**Rating:** 4.0/5.0 stars

**Reviewed by:** Wendy B. | dōTERRA Essential Oils IPC# 357360, Consumer Services, Small-Business (50 or fewer emp.)

**Reviewed Date:** December 04, 2017

**What do you like best about Cortex XDR?**

Secdo has a quick response time once problems are identified.

**What do you dislike about Cortex XDR?**

There's not much that I don't like about this.

**What problems is Cortex XDR solving and how is that benefiting you?**

Website security is of great importance to us.  We will get notified of customer information breaches

  ### 22. Good threat detection and response tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Bhavik P. | Technical Lead, Computer & Network Security, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 27, 2017

**What do you like best about Cortex XDR?**

Give complete information of threat from source to destination communication, can be integrated with SIEM and very good graphical representation of threat flow

**What do you dislike about Cortex XDR?**

As of now we did not found any thing.....

**What problems is Cortex XDR solving and how is that benefiting you?**

End to end Analytic for threat


## Cortex XDR Discussions
  - [What is Cortex XDR?](https://www.g2.com/discussions/what-is-cortex-xdr) - 1 comment

- [View Cortex XDR pricing details and edition comparison](https://www.g2.com/products/palo-alto-networks-cortex-xdr/reviews?filters%5Bnps_score%5D%5B%5D=4&section=pricing&secure%5Bexpires_at%5D=2026-08-14+19%3A29%3A50+-0500&secure%5Bsession_id%5D=81e2d43b-6d22-47f2-8b54-d179b6a70637&secure%5Btoken%5D=792a08c8a1ad8817ae6dc2e9db032fa1e43af60816aeb81a3fe9c3998857d913&format=llm_user)
## Cortex XDR Integrations
  - [Amazon Simple Storage Service (S3)](https://www.g2.com/products/amazon-simple-storage-service-s3/reviews)
  - [Google Cloud Storage](https://www.g2.com/products/google-cloud-storage/reviews)
  - [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  - [Google Workspace](https://www.g2.com/products/google-workspace/reviews)
  - [Graylog](https://www.g2.com/products/graylog/reviews)
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  - [Palo Alto Networks Next-Generation Firewalls](https://www.g2.com/products/palo-alto-networks-next-generation-firewalls/reviews)
  - [RadarQ](https://www.g2.com/products/radarq/reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

## Cortex XDR Features
**Additional Functionality**
- Penetration Testing
- Alerts/Notifications
- Audit Trail
- Anti Virus
- Vulnerability Scanning
- Remote Monitoring & Management
- VPN
- Behavior Analytics
- Reporting/Analytics
- Real-Time Notifications
- Access Controls/Permissions
- SSL Security
- Patch Management
- Event Logs
- Anomaly/Malware Detection
- DNS Leak Protection
- Third-Party Integrations
- Server Monitoring
- Real-Time Monitoring
- Compliance Management
- Network Provisioning
- API
- Email Alerts
- Security Auditing
- Intrusion Detection System
- Data Visualization
- Two-Factor Authentication
- Generative AI
- Firewalls
- AI Copilot
- Anti Spam
- Threat Response
- Activity Monitoring
- Risk Alerts
- Data Loss Prevention
- Single Sign On
- Intrusion Prevention System
- Secure Login
- Policy Management
- Activity Dashboard

**Administration**
- Compliance
- Web Control
- Application Control
- Asset Management
- Device Control
- Patch Management
- Password Management
- Compliance Management
- Remote Monitoring & Management
- Workflow Management
- Policy Management
- Assessment Management
- Endpoint Management
- Incident Management
- User Management
- Audit Management
- PCI Compliance
- Web Threat Management
- Device Management

**Analysis**
- Incident Reporting
- Network Visibility
- Metadata Enrichment
- Metadata Management

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection
- Threat Response

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Additional Functionality**
- Generative AI
- Event Analysis
- Prioritization
- AI Copilot
- Whitelisting/Blacklisting
- Remediation Management
- Alerts/Notifications
- Behavioral Analytics
- Continuous Monitoring
- Root Cause Analysis
- Endpoint Management
- Anomaly/Malware Detection

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- System Isolation
- Firewall
- Endpoint Intelligence
- Anomaly/Malware Detection

**Response**
- Incident Alerts
- Response Orchestration
- Response Automation

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility
- API

**Security**
- Data Security
- Data loss Prevention
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Analysis**
- Automated Remediation
- Incident Reports
- Behavioral Analysis
- Risk Analysis
- Customizable Reports
- Summary Reports

**Detection**
- Multi-Network Monitoring
- Asset Discovery
- Anomaly Detection

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Real-Time Analytics
- Collaboration Tools
- Secure Login
- AI/Machine Learning
- Single Sign On
- Behavioral Analytics
- Prioritization
- Reporting & Statistics
- IOC Verification
- Monitoring
- Two-Factor Authentication
- Server Monitoring
- Vulnerability Scanning
- Activity Tracking
- Event Logs
- Risk Assessment
- Real-Time Notifications
- Real-Time Monitoring
- Whitelisting/Blacklisting
- Activity Monitoring
- Alerts/Notifications
- Risk Alerts
- Behavior Tracking
- Tokenization
- Web Traffic Reporting
- Generative AI

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Detection and Response (CDR)**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Services - Network Detection and Response (NDR)**
- Managed Services

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Services - Extended Detection and Response (XDR)**
- Managed Services

**Services - Cloud Detection and Response (CDR) **
- Managed Services

**Additional Functionality**
- Mobile Access
- IT Asset Management
- Reporting/Analytics
- Data Import/Export
- Encryption
- Remediation Management
- Root Cause Analysis
- Customization
- Workflow Management
- Incident Management
- User Management
- Behavioral Analytics
- Ransomware Protection
- Activity Dashboard
- AI Copilot
- Data Security
- Authentication
- Firewalls
- Collaboration Tools
- Endpoint Protection
- Cloud Application Security
- Third-Party Integrations
- Access Controls/Permissions
- Alerts/Notifications
- Data Analysis Tools
- Risk Management
- Generative AI
- Network Scanning
- Vulnerability Management
- Search/Filter

## Top Cortex XDR Alternatives
  - [Sophos Endpoint](https://www.g2.com/products/sophos-endpoint/reviews) - 4.7/5.0 (793 reviews)
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (418 reviews)
  - [ESET PROTECT](https://www.g2.com/products/eset-protect/reviews) - 4.6/5.0 (963 reviews)

