---
title: Cortex XDR Reviews
meta_title: 'Cortex XDR Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 85 reviews by the users' company size, role or industry to
  find out how Cortex XDR works for a business like yours.
aggregate_rating:
  rating_value: 4.5
  review_count: 85
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: Cloud Security
  url: https://www.g2.com/categories/cloud-security
---


# Cortex XDR Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Extended Detection and Response (XDR) Platforms](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms)  
**Average Rating:** 4.5/5.0  
**Total Reviews:** 85
## About Cortex XDR
Cortex XDR is the industry’s first extended detection and response platform that stops modern attacks by integrating data from any source. With Cortex XDR, you can harness the power of AI, analytics and rich data to detect stealthy threats. Your SOC team can cut through the noise and focus on what matters most with intelligent alert grouping and incident scoring. Cross-data insights accelerate investigations, so you can streamline incident response and recovery. Cortex XDR delivers peace of mind with best-in-class endpoint protection that achieved the highest combined protection and detection scores in the MITRE ATT&amp;CK® round 3 evaluation. The Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic protection to secure what’s next.



## Cortex XDR Pros & Cons
**What users like:**

- Users value the **important alert notifications** from Cortex XDR, which enhance security without overwhelming them. (2 reviews)
- Users appreciate the **simplicity and manageability** of Cortex XDR, finding it easy to navigate and utilize effectively. (2 reviews)
- Users love the **unique features** of Cortex XDR, especially its effective threat detection without compromising system speed. (2 reviews)
- Users praise the **unified detection and response capability** of Cortex XDR, enhancing threat investigation efficiency and accuracy. (2 reviews)
- Users value the **unified detection and response capability** of Cortex XDR for swift and precise threat investigations. (2 reviews)
- AI (1 reviews)
- AI Technology (1 reviews)
- Alerting (1 reviews)
- Alerts (1 reviews)
- Users appreciate the **effective antivirus protection** of Cortex XDR, as it quickly detects and handles various threats. (1 reviews)

**What users dislike:**

- Users find **limited features** in Cortex XDR, with restrictions affecting core OS functionalities and usability issues on lower-end systems. (2 reviews)
- Users experience a **noticeable performance impact** on lower-end systems with the Cortex XDR agent installed. (1 reviews)
- Users face **compatibility issues** with Cortex XDR, restricting core functionalities and software installations on their machines. (1 reviews)
- Users find the **system complexity** challenging, often struggling with management and a steep learning curve. (1 reviews)
- Users find the **complex management** of Cortex XDR challenging due to its steep learning curve and customization difficulties. (1 reviews)
- Users find the **difficult learning curve** challenging, especially when managing policies and customizing detections in Cortex XDR. (1 reviews)
- Users find the Cortex XDR to be **expensive** for public school systems, but value its worth despite the cost. (1 reviews)
- Users note the **restrictive core functionalities** of Cortex XDR, limiting certain installations and affecting usability. (1 reviews)
- High Resource Usage (1 reviews)
- Users face **installation difficulties** with Cortex XDR, as it restricts some core OS functionalities during setup. (1 reviews)

## Cortex XDR Reviews
  ### 1. Cortext XDR - Good AV

**Rating:** 4.5/5.0 stars

**Reviewed by:** Ashley M. | System Administrator, Enterprise (> 1000 emp.)

**Reviewed Date:** January 13, 2022

**What do you like best about Cortex XDR?**

Centralised management interface and stability of client

**What do you dislike about Cortex XDR?**

Agent was unstable once or twice on inital update

**What problems is Cortex XDR solving and how is that benefiting you?**

Early protection from virus threats

  ### 2. Cortex XDR best in Endpoint Protection and also provides Wealth of information from Endpoint

**Rating:** 5.0/5.0 stars

**Reviewed by:** Tony I. | Snr Security analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** May 06, 2021

**What do you like best about Cortex XDR?**

Ease of use and details information provided from Endpoints. Cortex XDR also detects threats with behavioral analytics more accurately and allows you to contain and isolate endpoints quickly before any damage is done.

**What do you dislike about Cortex XDR?**

Cortex XDR does not currently allow us to download Policies, thereby making it difficult to audit applied policies Easily.

**What problems is Cortex XDR solving and how is that benefiting you?**

Problem: Ensuring Endpoints are protected using both signature and behavioral pattern
benefit: Tight integration with enforcement points accelerates containment, enabling you to stop attacks before the damage is done.

  ### 3. Best tool to avoid security attacks like DDOS

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 18, 2021

**What do you like best about Cortex XDR?**

speed up the  RCA investivation of unwanted security attacks with analytics
Easy to use
Nominal charges
Offers endpoint management

**What do you dislike about Cortex XDR?**

Nothing to be disliked about this  product

**What problems is Cortex XDR solving and how is that benefiting you?**

Investigating and eliminating security attacks
Endpoint management

  ### 4. Execute network-wide information security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Billy S. | IT Specialist, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 10, 2019

**What do you like best about Cortex XDR?**

It is very helpful to handle the various operational requirements of firewalls with Palo Alto. It allows you to build shared laws which can be enforced in many proxy servers. It also utilizes software actions to spot hostility and prevent our system.  As each category of firewalls has different uses, Palo Alto helps to detect if there are unidentified devices that generate unwanted traffic and what sort of traffic it is. Also, filters introduced between organizational sessions in several areas are able to remain permanent.

**What do you dislike about Cortex XDR?**

It is very helpful to handle the various operational requirements of firewalls with Palo Alto. It allows you to build shared laws which can be enforced in many proxy servers. It also utilizes software actions to spot hostility and prevent our system.  As each category of firewalls has different uses, Palo Alto helps to detect if there are unidentified devices that generate unwanted traffic and what sort of traffic it is. Also, filters introduced between organizational sessions in several areas are able to remain permanent.

**Recommendations to others considering Cortex XDR:**

Palo Alto Panorama is a great option if in your workplace there are specific conditions for various firewall classes. It allows you to track aspects such as scheduling and tools that are accessible. However, the effective tracking system has its flaws, that's why I don't consider it as an all-in solution.

**What problems is Cortex XDR solving and how is that benefiting you?**

We use Palo Alto for unified firewall monitoring and regulation of the execution of network-wide information security. We attempted other AV services, but at some stage they all crashed and Palo Alto Panorama have rarely disappointed us.

  ### 5. Handle all of our settings at all of our distinct locations

**Rating:** 4.5/5.0 stars

**Reviewed by:** Pedro C. | IT Specialist, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 08, 2019

**What do you like best about Cortex XDR?**

Palo Alto Traps is very helpful for updating the majority of the software by a single tap. The Control Panel and the ACC provide helpful data to display all firewalls or to be able to select which one we want to work with.  

**What do you dislike about Cortex XDR?**

We switch from local to the cloud variant of Traps, as in the cloud version's there were almost no training alternatives, which have changed over time.  Also, sometimes the PANOS extension to the firewalls merely stops working with no particular reason. In general, I think the system does not have a big customer environment. Also, it appears to be too severe (so much that’s unnecessary) when any small threat is detected.

**Recommendations to others considering Cortex XDR:**

If a customer wishes to readily handle the configurations, or want to handle firewall backups without running between so many cabinets, Palo Alto Traps is vital and straightforward.  However, you must consider that this tool is not meant to be used as a tool for monitoring your system.

**What problems is Cortex XDR solving and how is that benefiting you?**

Palo Alto Traps is used by our network safety group to handle all of our settings at all of our distinct locations. Only IT staff are responsible for device management of these tools.  It is also used to implement central console patches and press strategies. I think of Palo Alto Traps as a useful method to retain data and to maintain the division of duties separate, as we can offer participants from other groups a little space to display the settings without providing them with immediate entry to the firewalls.

  ### 6. One of the better endpoint security products

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Fund-Raising | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 16, 2019

**What do you like best about Cortex XDR?**

Traps has prevented anomalous behavior in our environment a couple of times. This has saved us a lot of trouble. The management interface is intuitive and easy to comprehend. Agent impact on performance in negligible.

**What do you dislike about Cortex XDR?**

At the moment the rollout on MacOS Cataline gave us a little headache, but as of today Traps supports Cataline. Just make sure you update Traps first to the newest version. Otherwise you have to uninstall Traps and reinstall the new version. 
I don't like to way to create Agent Installations. For every new version you create a new installation "package". You should never delete it as long as machines make use of that installation.Just hide them. But it feels this could be done easier.

**Recommendations to others considering Cortex XDR:**

Definitely try Palo Alto Traps as one of your choices if you are looking for a new product. Especially if you have more Palo Alto products.

**What problems is Cortex XDR solving and how is that benefiting you?**

A legacy signature based antivirus doesn't work nowadays. You need behavior based detection. Traps has this and is a full replacement for a signature based antivirus. As admins we feel a lot more at ease.

  ### 7. Great Next Gen Antivirus

**Rating:** 5.0/5.0 stars

**Reviewed by:** Joe W. | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 28, 2018

**What do you like best about Cortex XDR?**

The ability to configure it and know that it will auto update without needing regular input. 

**What do you dislike about Cortex XDR?**

If a piece of software gets updated that you have whitelisted by hash control, it can re trigger after each update. This only happens with smaller oneoff software the system hasnt seen before, 

**Recommendations to others considering Cortex XDR:**

This is a great product and we couldn't be happier with it. If you need something that wont require having someone look at every issue in it and fix issues daily, this is a great fit. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Palo Alto is our primary antivirus and ransomware protection. 

  ### 8. Excellent threat hunting capabilities 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** January 24, 2018

**What do you like best about Cortex XDR?**

that with secdo our security team is really able to be proactive and not just handle alerts in a reactive way. Because we handle alerts faster, we have time to threat hunt – based on leads, IOCs or even behavioral IOCs we created in secdo. 

And because they record all endpoint activity and store it for months – we can really hunt. We can find advanced, fileless, and in-memory attacks, and go deep into suspicious activity to identify anomalies that could lead to silent threats. 


**What do you dislike about Cortex XDR?**

I am waiting for them to add some features we asked for, but other than that - none. 

**What problems is Cortex XDR solving and how is that benefiting you?**

the biggest problem we had is the lack of time and tools to effectively hunt for threats that our detection/protection systems didn’t catch. So with Secdo our tier1 analysts handle most alert WORK, and the Tier 2/3 can actually have time to hunt. and the hunting is really granular and depth – because they store endpoint activity and let you search everything. We actually found hidden threats in our network already a week after we start using Secdo. It’s a really useful tool for sec teams 

  ### 9. EDR with focus on SOC problems, very good 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 28, 2017

**What do you like best about Cortex XDR?**

Most EDR vendors focus on the detection and prevention part. But our security team focuses on the part of collecting endpoint information, investigating alerts, responding to threats and hunt for new ones. Secdo is one of the only vendors who focuses on solving the real problems that SOC teams are facing. We have enough alerts coming in from all of our detection and prevention systems – the problem we have is dealing with them  - and SECDO is very good at that. I really recommend

**What do you dislike about Cortex XDR?**

It’s not that I dislike, but Secdo is meant to be used by matured SOC teams. If you are a “one man show” doing security operations – Secdo is probably not for you. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Reducing risk. We don’t miss any alerts so we don’t miss threats, and this reduces the chances of having a breach (which we all know we can’t 100% avoid) become a data breach.  That’s the key benefit for us, so even if an attack has succeeded, we will catch it and respond to it fast enough to make sure it doesn’t have time to actually do any harm in our network. 

  ### 10. Great combination of EDR with security automation

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Consumer Goods | Small-Business (50 or fewer emp.)

**Reviewed Date:** January 02, 2018

**What do you like best about Cortex XDR?**

We're aware of some of the top EDRs - None of them gives an automation layer that would allow insight to investigate incidents and alerts automatically.
That’s a game changer for us – instead of drilling into each alert and trying to match it with the relevant endpoint data – Secdo does that automatically for us (they call the algorithm that does that ‘causality analysis engine’).

**What do you dislike about Cortex XDR?**

Orchestration would be a great add on for such a product

**Recommendations to others considering Cortex XDR:**

Definitely get involved with this product - it's ease of use, ability to drill down and coverage at volume would make your life easier !

**What problems is Cortex XDR solving and how is that benefiting you?**

we don't have the capacity to investigates all of our daily alerts.
Secdo allows us to get better coverage, about 30 times the coverage which is unbelievable !

  ### 11. SecDo Host visibility – for IT and Security

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Enterprise (> 1000 emp.)

**Reviewed Date:** January 02, 2018

**What do you like best about Cortex XDR?**

Their endpoint visibility capabilities. From what I’ve seen in other EDR tools, they
have 3 advantages:
 Thread level visibility (all others do process level visibility)
 They keep all endpoint data that they collect for a minimum of 30 days (all
the other vendors keep it up to 30 days)
 They collect way more endpoint activity types then other EDRs, so they also
cover uses cases as insider threats, business risk, user activity, policy
violations, System/File attribute violations, etc.)

**What do you dislike about Cortex XDR?**

That they don’t also have an EPP solution. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Before Secdo, both the IT team and the security team were lacking information
about what’s going on our endpoints. We needed it for IT inventory, compliance, and
risk assessment, and for insider threats. So we searched for EDR tools that have the
most granular endpoint visibility. We tested 5 and decided about Secdo. With Secdo
we can query the endpoint population to identify areas of risk and possible
vulnerabilities (we see into USB activity, installed software, autoruns, downloaded
files, running drivers, and even captures of users’ screens)

  ### 12. ELEKS bolsters its security services by partnering with Secdo

**Rating:** 4.0/5.0 stars

**Reviewed by:** Iurii G. | Head of Corporate Security, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** October 30, 2017

**What do you like best about Cortex XDR?**

I’m pleased to introduce the ELEKS new security service portfolio powered by Secdo. Secdo’s preemptive incident response platform allows slashing the incident response time from months to minutes. We are happy to use this solution in-house as well as to recommend it to our customers. This partnership brings a strong security support to our business and allows us to offer improved security services to our clients.

**What do you dislike about Cortex XDR?**

Often we need some additional functionality (flexible reporting for instance), more visibility into agents and their hardening from the solution itself. Anyway, Secdo team is amazingly professional and we have it within days or already in the product roadmap.

**What problems is Cortex XDR solving and how is that benefiting you?**

- ELEKS quickly and cost-effectively introduced new services – prompt incident response, threat-hunting. 
- We are able to perform remote response without impacting business productivity, remote remediation while end-users continue to work.

  ### 13. Next Gen Anti Virus - Finally ready for the marketr

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Entertainment | Enterprise (> 1000 emp.)

**Reviewed Date:** May 05, 2018

**What do you like best about Cortex XDR?**

We have used traps for 2 years now and the 5.0 platform solves so many of the current issues. The interface is 100x better and the application protects us the way it should.

**What do you dislike about Cortex XDR?**

My only complaint is that you still cant use the traps client as a palo alto identity source for User ID.

**Recommendations to others considering Cortex XDR:**

Take a look at Traps and carbon black. They are both great next gen firewalls.

**What problems is Cortex XDR solving and how is that benefiting you?**

Protection from Malware/Spyware/Ransomware.

  ### 14. Well done product, it's give us eyes where we ware blinds.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Banking | Enterprise (> 1000 emp.)

**Reviewed Date:** September 13, 2017

**What do you like best about Cortex XDR?**

the search is quick, i can't say that we are blinds anymore. the customer service is extraordinary. definitely  great value for the product. ha

**What do you dislike about Cortex XDR?**

Heart beat is not exists in the product, so we are bare for technical issue. 

**Recommendations to others considering Cortex XDR:**

I think that if you really want to understand Secdo, you have to go to one of their conventions, it's clarify many things about the product, and bring visual view of how it's operate.
I didn't experienced with Carbon Black and  know how good the product only by rumors , so I think that there is a head to head fight between those to leaders and in my opinion Secdo are definitely on the right path to become the main leader in Incident Respond market. 

**What problems is Cortex XDR solving and how is that benefiting you?**

I can hardly say that we has business issues, it really looks like that SecDo make lots of effort to make the customers satisfy. 

  ### 15. A better handle on breach damage than anything else we have tried

**Rating:** 5.0/5.0 stars

**Reviewed by:** Chen R. | account manager, Telecommunications, Enterprise (> 1000 emp.)

**Reviewed Date:** June 22, 2017

**What do you like best about Cortex XDR?**

We are in a situation now where we have to justify every expenditure, even for cyber security. We have to quantify, quantify, quantify! Fortunately, there are a lot of published metrics regarding the costs of data breaches, even down to the single data record. Our cyber security products can no longer justify themselves by “providing security”. When we acquire a new product, it has to show us that it brings real, quantifiable value. Secdo’s ability to fully assess damage from any breach gives us a vital metric to report. To me, that’s far more useful than just the incident response part. It gives us the cost and value of the way we do incident response.     



**What do you dislike about Cortex XDR?**

Nothing at all.
couldnt find anything to dislike 



**What problems is Cortex XDR solving and how is that benefiting you?**

Secdo gives us a better handle on breach damage than anything else we have tried. To date, we are able to quantify data leaks so some degree. We are on the road toward establishing metrics for our incident response and Secdo is helping us.



  ### 16. EDR system Secdo for analyst

**Rating:** 5.0/5.0 stars

**Reviewed by:** Vitalii S. | Senior Information Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** October 31, 2017

**What do you like best about Cortex XDR?**

From my side I would like to mentioned that Secdo is very good solution for analyst,because:
-  solution automatically generates incident process three for analyst.
-  allow to immediately add behavior indicators of compromise of malware.
-  upload file samples to the VirusTotal.
-  allow immediate incident response.   

**What do you dislike about Cortex XDR?**

There is not any options in Secdo which I dislike,but I hope that in future company will  have automatic IOC integration process . 

**What problems is Cortex XDR solving and how is that benefiting you?**

Immediate incident response of incident.

  ### 17. Best way to forensics/investigate workstations 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Shay K. | security expert, Computer & Network Security, Enterprise (> 1000 emp.)

**Reviewed Date:** October 29, 2017

**What do you like best about Cortex XDR?**

easy to use, give eyes on incidents and processes which are relevant.
integration with arcsight siem is easy and gives another way of incidents response  

**What do you dislike about Cortex XDR?**

no linux agent waiting for linux agent it's on working plan

**What problems is Cortex XDR solving and how is that benefiting you?**

Reducing false positives and automating how we deal with incidents while not increasing resources, also the thread level endpoint visibility is defiantly useful

  ### 18. The Best Incident Response and Forensics platform these days!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Felix K. | Cyber Security Engineer, Computer & Network Security, Enterprise (> 1000 emp.)

**Reviewed Date:** December 28, 2017

**What do you like best about Cortex XDR?**

Simplicity Investigation and getting value from data

**What do you dislike about Cortex XDR?**

the product demands very high resources, due to its complexity and capabilities,

**What problems is Cortex XDR solving and how is that benefiting you?**

Investigate incidents on workstations, Integration with SIEM

  ### 19. Reliable software

**Rating:** 4.0/5.0 stars

**Reviewed by:** Wendy B. | dōTERRA Essential Oils IPC# 357360, Consumer Services, Small-Business (50 or fewer emp.)

**Reviewed Date:** December 04, 2017

**What do you like best about Cortex XDR?**

Secdo has a quick response time once problems are identified.

**What do you dislike about Cortex XDR?**

There's not much that I don't like about this.

**What problems is Cortex XDR solving and how is that benefiting you?**

Website security is of great importance to us.  We will get notified of customer information breaches

  ### 20. Came CIO

**Rating:** 5.0/5.0 stars

**Reviewed by:** Massimiliano T. | Enterprise (> 1000 emp.)

**Reviewed Date:** October 06, 2017

**What do you like best about Cortex XDR?**

The possibility to protect the endpoint from malware and exploits even when not connect to the corporate network
I like a lot the possibility to dismiss classical antivirus system.
I appreciate a lot the easy delivery and installation as well.


**What do you dislike about Cortex XDR?**

Nothing particoularly, but the full integration with Mac world would be appreciated.

**What problems is Cortex XDR solving and how is that benefiting you?**

Possibility for smartworkers to be always protected.

  ### 21. solving a huge IT hassle

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Broadcast Media | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 15, 2017

**What do you like best about Cortex XDR?**

In the IT department, we like being able to remediate endpoints from our own office. We don’t like to have to walk all over the campus to collect computers, bring them back and wipe them. It’s a pain. Secdo gives us very cool remote remediation tools so that we can pinpoint bad processes and quarantine them. We don’t have to disturb the user to do all this. Less hassle for everybody.


**What do you dislike about Cortex XDR?**

Frankly, this Secdo business is new and not all the IT people are on board. There are still some “old-timers” who cannot get off their insistence that all infected endpoints have to be wiped and re-imaged. Over time, we will convince them that our method with Secdo is way more efficient. 


**What problems is Cortex XDR solving and how is that benefiting you?**

At the end of the day, Secdo cuts remediation time and bother. That’s what will win the budget battle. As we log more remediation time with Secdo, more people are coming to see that we can reduce our budget and remediate much quicker than before. 


  ### 22. Sedco

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Higher Education | Enterprise (> 1000 emp.)

**Reviewed Date:** December 26, 2017

**What do you like best about Cortex XDR?**

Sedco help us to secure our systems according to our environment.enables security operations of slash the incident response

**What do you dislike about Cortex XDR?**

There is nothing cons according to me so nothing.

**What problems is Cortex XDR solving and how is that benefiting you?**

Help us to reduce our work. These security operations make our work get finished in minutes which save our team time

  ### 23. Great Visibility!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 22, 2017

**What do you like best about Cortex XDR?**

I like the visibility we get with Secdo. We can look for anything across our entire farm

of servers and endpoints and find what’s running where. We can see who uses which

application and how frequently. When someone complains that their endpoint is

slow, we can look into any time period in the past and find out what the

performance of the machine was including the processes. Then, we know what was

going on and why the user is complaining.

**What do you dislike about Cortex XDR?**

Nothing                                                                                                              

**What problems is Cortex XDR solving and how is that benefiting you?**

We get clobbered with performance complaints and we have to react quickly

sometimes. Users have no patience when they can’t get their work done. Being able to

see and quantify the problem and then being able to remediate it sure make us more

efficient and keeps our users a lot happier.

  ### 24. It’s a game changer

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 27, 2017

**What do you like best about Cortex XDR?**

A lot of people who are not necessarily involved in hard-core cyber security think that the goal is to automate everything. There are still a lot of incidents that you can’t and you don’t even want automated – you need human ingenuity to understand. I like that, with Secdo, I can get all the information I need to make the best decisions especially on highly complex cases.     

**What do you dislike about Cortex XDR?**

Nothing really. The product performs better than I expected

**What problems is Cortex XDR solving and how is that benefiting you?**

I guess you would say that we are concerned with keeping our data safe. With so many endpoints and as the target of some very serious attacks, we have to respond rapidly. Secdo has made the whole team way smarter when it comes to dealing with the real hard stuff. 

  ### 25. Secdo

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** December 28, 2017

**What do you like best about Cortex XDR?**

It is easy and intuitive and does the job

**What do you dislike about Cortex XDR?**

It is rather expensive and too many options 

**What problems is Cortex XDR solving and how is that benefiting you?**

Secdo's automated incident response platform hunts threats in real time and delivers an endpoint detection and response solution.

  ### 26. Incident response automation is not a myth 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Marketing and Advertising | Small-Business (50 or fewer emp.)

**Reviewed Date:** September 27, 2017

**What do you like best about Cortex XDR?**

The cyber kill chain tracking, Secdo shows us the attack to a thread level.
Very easy to use even for new analysists
IOC/BIOC rules allow turning incidents into rules to provide future threats 
Integrates easily with all our security tools 

**What do you dislike about Cortex XDR?**

Nothing yet will keep you updated if we have any issues 

**What problems is Cortex XDR solving and how is that benefiting you?**

Reducing false positives and automating how we deal with incidents while not icreasing resources, also the thread level endpoint visibility is defiantly useful 

  ### 27. Automated Alert Investigation

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer Networking | Small-Business (50 or fewer emp.)

**Reviewed Date:** November 04, 2017

**What do you like best about Cortex XDR?**

UNMATCHED, ZERO-GAP VISIBILITY OF ALL HOST ACTIVITY

**What do you dislike about Cortex XDR?**

FOUND IT HARD TO USE AS ITS NOT SEEMS TO BE USERFRIENDLY

**What problems is Cortex XDR solving and how is that benefiting you?**

With sedco we are able to bring the volume of suspicious alerts from 500 to 20 a day.

  ### 28. Quick response   

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Medical Devices | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 09, 2017

**What do you like best about Cortex XDR?**

It's easy to see what's happening at our endpoints across the board and see who uses what service/application. 

**What do you dislike about Cortex XDR?**

nothing in particular that I can point to.

**What problems is Cortex XDR solving and how is that benefiting you?**

We get to solve problems for users more quickly, so that people are not frustrated for having to stop working when an incident occurs. 

  ### 29. QUality

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Telecommunications | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 06, 2017

**What do you like best about Cortex XDR?**

Ease of use and quality . User friendly interface 

**What do you dislike about Cortex XDR?**

Nothing I can think of at this point of time 

**What problems is Cortex XDR solving and how is that benefiting you?**

Customer experience 

  ### 30. SECDO Feedback

**Rating:** 4.5/5.0 stars

**Reviewed by:** Shailendra S. | VP Asia, Sales, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** August 07, 2017

**What do you like best about Cortex XDR?**

Its one of the most focused vendor on IR. Where as all other vendors are EDR focusing less on IR, most important thing for any organisation.

**What do you dislike about Cortex XDR?**

Less marketing investment. No linux capabilities

**What problems is Cortex XDR solving and how is that benefiting you?**

Endpoint Monitoring for investigation and quick analysis.

  ### 31. Good threat detection and response tool

**Rating:** 4.0/5.0 stars

**Reviewed by:** Bhavik P. | Technical Lead, Computer & Network Security, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 27, 2017

**What do you like best about Cortex XDR?**

Give complete information of threat from source to destination communication, can be integrated with SIEM and very good graphical representation of threat flow

**What do you dislike about Cortex XDR?**

As of now we did not found any thing.....

**What problems is Cortex XDR solving and how is that benefiting you?**

End to end Analytic for threat

  ### 32. Best Incident Response platform I've worked with...

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 06, 2016

**What do you like best about Cortex XDR?**

The excellent incident response capabilities. I’ve never seen anything like it – the ability to investigate and remediate threats in literally minutes.

**What do you dislike about Cortex XDR?**

Nothing I can think of – it’s really fantastic.

**Recommendations to others considering Cortex XDR:**

If you deal with a lot of security alerts and don’t have the manpower to investigate all of them – Secdo is the tool for you. It also has amazing remediation capabilities – all from one place without the need to install additional tools on the endpoint.

**What problems is Cortex XDR solving and how is that benefiting you?**

Our customers are large Enterprises that have SOC teams or incident response teams that need to deal with overwhelming amounts of alerts generated from prevention and detection systems they have. They use Secdo to validate and investigate the alerts automatically, and once a real threat has been found – they use Secdo to remediate the alerts surgically. With Secdo they are able to deal with all alerts and reduce time for investigation from days to minutes.

  ### 33. Excellent to manage 'false positives' alerts emanating from a SIEM

**Rating:** 5.0/5.0 stars

**Reviewed by:** Vilaas B. | Business Development, Information Technology and Services, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 25, 2016

**What do you like best about Cortex XDR?**

Three things
1. The speed with which the root cause to an alert can be identified
2. The activity of the suspected host
3. Remediation/ freeze from the console.

It seems to provide the ability to compress the investigation / visibility / response capabilities timeframes.

Another highlight is the ability to fight ransomware attacks. 

**What do you dislike about Cortex XDR?**

Trying to figure that out. currently, seem to like what I am seeing.

**Recommendations to others considering Cortex XDR:**

A good product/ solution fit if you are considering Behavioral/ threat analytics. The analytics and remediation is pretty intuitive and considering the technology space is not too old, SECDO is doing a good job with cyber security requirements.

**What problems is Cortex XDR solving and how is that benefiting you?**

Defense for ransomware attacks
Reduce timeframes and hence manage the huge false positives emanating from the SIEM infrastructure

  ### 34. SECDO to the rescue 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 25, 2016

**What do you like best about Cortex XDR?**

Blocking Ransomware for real!
Enables investigation on hosts over time without the need of expensive forensics products nor system experts. 

**What do you dislike about Cortex XDR?**

we needed response tools (isolating host and run commands remotely) but SECDO solution now included them. 

**Recommendations to others considering Cortex XDR:**

Make sure you have strong bi-directional communication with your SIEM (most important for handling alerts and automation of alerts on workstations. 

**What problems is Cortex XDR solving and how is that benefiting you?**

Ransomware blocking
We now can search for same evidences cross company in minutes. 

  ### 35. Hunting & Investigating by SECDO gives the ability to disassemble any attack to its parts

**Rating:** 5.0/5.0 stars

**Reviewed by:** Guy L. | Cyber & Information Security Team Leader, Computer & Network Security, Small-Business (50 or fewer emp.)

**Reviewed Date:** October 25, 2016

**What do you like best about Cortex XDR?**

visibility
effectiveness
low fingerprint
easy to use
false positive reduction
root cause analysis

**What do you dislike about Cortex XDR?**

Endpoint Agent is Required















**What problems is Cortex XDR solving and how is that benefiting you?**

Security Products false positives 
Endpoint Visibility
Remote Control over endpoints
Historical Investigation 


## Cortex XDR Discussions
  - [What is Cortex XDR?](https://www.g2.com/discussions/what-is-cortex-xdr) - 1 comment

- [View Cortex XDR pricing details and edition comparison](https://www.g2.com/products/palo-alto-networks-cortex-xdr/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-08-10+01%3A16%3A07+-0500&secure%5Bsession_id%5D=72f93ab4-5b0d-4a9a-a7e1-3243ab380a40&secure%5Btoken%5D=0bb0f6ed3c3770743fc2fb4dd8049b232dbdab53b74c39de350fba606883722b&format=llm_user)
## Cortex XDR Integrations
  - [Amazon Simple Storage Service (S3)](https://www.g2.com/products/amazon-simple-storage-service-s3/reviews)
  - [Google Cloud Storage](https://www.g2.com/products/google-cloud-storage/reviews)
  - [Google Security Operations](https://www.g2.com/products/google-security-operations/reviews)
  - [Google Workspace](https://www.g2.com/products/google-workspace/reviews)
  - [Graylog](https://www.g2.com/products/graylog/reviews)
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)
  - [Palo Alto Networks Cortex XSOAR](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews)
  - [Palo Alto Networks Next-Generation Firewalls](https://www.g2.com/products/palo-alto-networks-next-generation-firewalls/reviews)
  - [RadarQ](https://www.g2.com/products/radarq/reviews)
  - [Splunk Enterprise](https://www.g2.com/products/splunk-enterprise/reviews)

## Cortex XDR Features
**Additional Functionality**
- Penetration Testing
- Alerts/Notifications
- Audit Trail
- Anti Virus
- Vulnerability Scanning
- Remote Monitoring & Management
- VPN
- Behavior Analytics
- Reporting/Analytics
- Real-Time Notifications
- Access Controls/Permissions
- SSL Security
- Patch Management
- Event Logs
- Anomaly/Malware Detection
- DNS Leak Protection
- Third-Party Integrations
- Server Monitoring
- Real-Time Monitoring
- Compliance Management
- Network Provisioning
- API
- Email Alerts
- Security Auditing
- Intrusion Detection System
- Data Visualization
- Two-Factor Authentication
- Generative AI
- Firewalls
- AI Copilot
- Anti Spam
- Threat Response
- Activity Monitoring
- Risk Alerts
- Data Loss Prevention
- Single Sign On
- Intrusion Prevention System
- Secure Login
- Policy Management
- Activity Dashboard

**Administration**
- Compliance
- Web Control
- Application Control
- Asset Management
- Device Control
- Patch Management
- Password Management
- Compliance Management
- Remote Monitoring & Management
- Workflow Management
- Policy Management
- Assessment Management
- Endpoint Management
- Incident Management
- User Management
- Audit Management
- PCI Compliance
- Web Threat Management
- Device Management

**Analysis**
- Incident Reporting
- Network Visibility
- Metadata Enrichment
- Metadata Management

**Detection & Response**
- Response Automation
- Threat Hunting
- Rule-Based Detection
- Real-Time Detection
- Threat Response

**Services - Endpoint Detection & Response (EDR) **
- Managed Services

**Additional Functionality**
- Generative AI
- Event Analysis
- Prioritization
- AI Copilot
- Whitelisting/Blacklisting
- Remediation Management
- Alerts/Notifications
- Behavioral Analytics
- Continuous Monitoring
- Root Cause Analysis
- Endpoint Management
- Anomaly/Malware Detection

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**System Control**
- Device Control
- Web Control
- Application Control
- Asset Management
- System Isolation

**Functionality**
- System Isolation
- Firewall
- Endpoint Intelligence
- Anomaly/Malware Detection

**Response**
- Incident Alerts
- Response Orchestration
- Response Automation

**Management**
- Extensibility
- Workflow Automation
- Unified Visibility
- API

**Security**
- Data Security
- Data loss Prevention
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Vulnerability Prevention**
- Endpoint Intelligence
- Firewall
- Malware Detection

**Analysis**
- Automated Remediation
- Incident Reports
- Behavioral Analysis
- Risk Analysis
- Customizable Reports
- Summary Reports

**Detection**
- Multi-Network Monitoring
- Asset Discovery
- Anomaly Detection

**Analytics**
- Threat Intelligence
- Artificial Intelligence & Machine Learning
- Data Collection

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Real-Time Analytics
- Collaboration Tools
- Secure Login
- AI/Machine Learning
- Single Sign On
- Behavioral Analytics
- Prioritization
- Reporting & Statistics
- IOC Verification
- Monitoring
- Two-Factor Authentication
- Server Monitoring
- Vulnerability Scanning
- Activity Tracking
- Event Logs
- Risk Assessment
- Real-Time Notifications
- Real-Time Monitoring
- Whitelisting/Blacklisting
- Activity Monitoring
- Alerts/Notifications
- Risk Alerts
- Behavior Tracking
- Tokenization
- Web Traffic Reporting
- Generative AI

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Security Management**
- Incident Reports
- Security Validation
- Compliance 

**Agentic AI - Extended Detection and Response (XDR) Platforms**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Agentic AI - Cloud Detection and Response (CDR)**
- Autonomous Task Execution
- Proactive Assistance
- Decision Making

**Services - Network Detection and Response (NDR)**
- Managed Services

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Services - Extended Detection and Response (XDR)**
- Managed Services

**Services - Cloud Detection and Response (CDR) **
- Managed Services

**Additional Functionality**
- Mobile Access
- IT Asset Management
- Reporting/Analytics
- Data Import/Export
- Encryption
- Remediation Management
- Root Cause Analysis
- Customization
- Workflow Management
- Incident Management
- User Management
- Behavioral Analytics
- Ransomware Protection
- Activity Dashboard
- AI Copilot
- Data Security
- Authentication
- Firewalls
- Collaboration Tools
- Endpoint Protection
- Cloud Application Security
- Third-Party Integrations
- Access Controls/Permissions
- Alerts/Notifications
- Data Analysis Tools
- Risk Management
- Generative AI
- Network Scanning
- Vulnerability Management
- Search/Filter

## Top Cortex XDR Alternatives
  - [Sophos Endpoint](https://www.g2.com/products/sophos-endpoint/reviews) - 4.7/5.0 (794 reviews)
  - [CrowdStrike Falcon Endpoint Protection Platform](https://www.g2.com/products/crowdstrike-falcon-endpoint-protection-platform/reviews) - 4.6/5.0 (417 reviews)
  - [ESET PROTECT](https://www.g2.com/products/eset-protect/reviews) - 4.6/5.0 (963 reviews)

