Hunny B.
HB
Hunny B.
Network Engineer
Computer & Network Security
Enterprise (> 1000 emp.)
"Comprehensive Threat Detection with Efficient Response"
4/5
What do you like best about Cortex XDR?

I like Cortex XDR's ability to correlate data from multiple sources into a single instrument, which helps review hundreds of individual alerts by providing a complete attack timeline. This feature makes it easier for security teams to investigate and respond much faster. Its automated response capabilities, like isolating compromised endpoints and stopping malicious processes, are impressive because they help reduce the impact of an attack. Another aspect I appreciate is its centralized management, which allows security teams to monitor endpoints, investigate incidents, and respond from a single console, improving visibility and reducing investigation time. I also value the detailed attack timeline feature for simplifying root cause analysis. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

I haven't used cortex XDR in a prodcution environment, so i can't comment on its limitations from personla experience. However, based on my research and industry discussions, one are that can require attention is the initial tunning of detection policies to minimize false positives and ensure are meaningful. Review collected by and hosted on G2.com.

Dev S.
DS
Dev S.
Network Security Engineer
Mid-Market (51-1000 emp.)
"Robust Threat Detection, But a Steep Learning Curve"
4/5
What do you like best about Cortex XDR?

What I like most about Cortex XDR is how it connects the dots between tiny, suspicious events and the bigger attack story they're part of. That correlation view saves a lot of guesswork, and the behavioral detections tend to catch weird stuff early, even when there's no clear signature. It just feels like it gives us clarity when things are tried to state. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

I find the interface feels a little dense, with too many panels and options at once. As a new analyst, I feel overwhelmed until I get used to it. Also, it takes me time to get the alert tuning right because the alerts can be a bit noisy out of the box until I fine-tune the policy. Review collected by and hosted on G2.com.

Ajeet  U.
AU
Ajeet U.
Security Lead Consultant
Mid-Market (51-1000 emp.)
"A robust XDR platform which simplifies Threat Investigation"
5/5
What do you like best about Cortex XDR?

The user inerface is very well designed. The integrations is very easy in comparision of other third party security tools.

In performance prospective, The Endpoint agent is very lightweight and it consume minimal resouces on system in comparision of other security tools.

The cortex XDR provides premium service of XDR solution. it is a cost effective solution for any company/organizations that give priority strong security .

The support service is great and effecrive related to any troubleshooting or integrations. It has AI driven analytics and ML capabilities, which help detect unknown threats, risks and fileless attacks. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The licensing cost can be high for small or startup organizations or companies and the initialy setup and policy creation/policy tuning require experienced engineer or administrators Review collected by and hosted on G2.com.

Joshuva A.
JA
Joshuva A.
Cybersecurity Analyst
Enterprise (> 1000 emp.)
"Solid detection depth, but plan for a learning curve"
4.5/5
What do you like best about Cortex XDR?

We tested Cortex XDR as a proof of concept before committing to anything, and rolled the agent out to about 10 endpoints for roughly six weeks. What won me over was the incident view: instead of chasing a bunch of separate alerts, it pulled everything related into a single incident, complete with a process tree, so I could clearly see what happened and in what order. That saved a ton of back-and-forth.

The behavioral detection also caught a couple of the sneakier things we tested it with that I wasn’t sure it would pick up. XQL took a bit to get used to, but once it clicked, being able to hunt across endpoint and network data from one place was really handy. If your main priority is detection depth, that part feels solid. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

Honestly, there’s a bit of a learning curve. Getting comfortable with XQL and tuning it properly for our environment took longer than I expected, and the console can feel pretty busy when you’re just starting out. Rolling out the agent also took a few attempts before we got the policies set up the way we wanted. On top of that, sorting out pricing was more of a hassle than it should have been, it took some back-and-forth to understand what a full deployment would actually cost us. None of this killed the eval, but it’s the kind of friction a smaller team should know about going in. Review collected by and hosted on G2.com.

NK
Nilesh K.
Senior Security Engineer
Computer & Network Security
Mid-Market (51-1000 emp.)
"Top-Notch Security with Streamlined Incident Response"
4.5/5
What do you like best about Cortex XDR?

I am using Cortex XDR to secure our business infrastructure. It provides a NextGen antivirus that effectively blocks malware, ransomware, and other types of exploits and attacks. I like how it can correlate alerts from endpoints, networks, and other sources into a single management console and helps detect advanced threats like zero-day exploits. It's easy to get root cause analysis and identify attack patterns. Cortex XDR helps reduce the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) during investigations and responses to stakeholders in one place, which is very important because every second counts in cybersecurity. Deploying agents and configuring security profiles, firewall connectivity, and cloud infra tuning are all well-documented and easy to do. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

I find that I need proper training to use Cortex XDR effectively as a new analyst. Review collected by and hosted on G2.com.

Jaqueline V.
JV
Jaqueline V.
Student Software Developer
Small-Business (50 or fewer emp.)
"Powerful Security Tool with a Complex UI"
4.5/5
What do you like best about Cortex XDR?

I like Cortex XDR for its ability to connect related security events and patterns into an incident review, which helps analysts like me understand the full story behind an alert. This capability improves the quality of the labeled data and enhances analysis accuracy despite the initial complexity of the interface. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

I find that the platform provides too much security data, making it hard for me to identify important information quickly. Improving the organization of alert details, prioritizing key events, and providing clearer summaries would help me work more efficiently. A more customizable alert summary view that highlights the most important details at the beginning of an investigation could really streamline my process, offering a quick overview of key factors like the affected endpoint, user activity, process behavior, file reputation, network connections, and so on. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"Reliable XDR Platform for Security Teams"
4.5/5
What do you like best about Cortex XDR?

I like the strong threat detection and security visibility provided by Cortex XDR. It helps identify suspicious activities quickly and gives a clear view of incidents from one platform. The automated investigation features and real-time alerts help the security team respond faster. The dashboard is easy to understand, and integrations with other security tools improve overall workflow and efficiency. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The initial setup and configuration can take some time, especially for new users. Some advanced features may require extra learning and security knowledge to use properly. The interface is powerful, but a few areas could be made simpler to improve the experience for beginners. More detailed guidance and easier troubleshooting options would make the platform even better. Review collected by and hosted on G2.com.

Rohit B.
RB
Rohit B.
Assistant Manager - Endpoint Security
Insurance
Enterprise (> 1000 emp.)
"Streamlined Threat Detection with Some Setup Challenges"
4.5/5
What do you like best about Cortex XDR?

I like Cortex XDR for its noise reduction and automation, which saves time for the analysts. Its scalability and simplicity stand out to me. The faster root cause analysis with Cortex XDR improves the efficiency of our analysts and helps in simplifying operations. I also appreciate the readiness it provides. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The initial setup of Cortex XDR was quite complex for me, especially since the rollout was tedious and the policy tuning was very difficult due to our large environment. I found that training is often needed when new features are introduced, which can be challenging to keep up with. Additionally, I've faced integration challenges with third-party tools. The costs can also be an issue, and negotiating the bundle or selectively deploying add-ons is necessary to manage them effectively. Review collected by and hosted on G2.com.

AM
Amaan M.
Soc Analyst
Mid-Market (51-1000 emp.)
"Causality Engine Delivers Fast, End-to-End Attack Visibility"
4/5
What do you like best about Cortex XDR?

The endpoint agent and the causality engine really stand out for us. We came from a traditional EDR that generated a flood of separate alerts, so XDR’s ability to tie process, network, and user activity together into a single causal chain has been a big improvement. It lets analysts see the full story of an attack instead of piecing together fragments. Root-cause analysis that used to take an hour of pivoting now takes just minutes. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The management console has a steep learning curve. There are many nested menus, and finding specific settings or policies isn’t always intuitive. New analysts need real ramp-up time before they can be productive in the UI. Some workflows also require jumping between different sections of the console more than they should, which slows things down. Reporting is another weak spot. The built-in reports cover the basics, but anything customized for executive or compliance audiences typically means exporting data and building it elsewhere. Review collected by and hosted on G2.com.

Alessandro D.
AD
Alessandro D.
Technical Leader
Mid-Market (51-1000 emp.)
"Strong Correlation and Investigation Depth for SOC-Scale Threat Hunting"
4/5
What do you like best about Cortex XDR?

Cortex XDR stands out in day-to-day SOC operations for how effectively it correlates endpoint, network, and cloud telemetry into a single investigative view. As a Technical Lead managing a team of five analysts, I find the incident timeline and causality-chain visualization especially valuable for threat hunting and incident response—it significantly reduces the time needed to reconstruct an attack path versus piecing together logs across siloed tools. The behavioral analytics engine is also strong at detecting living-off-the-land techniques and lateral movement that signature-based tools often miss. Integration with the broader Cortex ecosystem (especially XSOAR for orchestration) further helps by enabling automation of repetitive triage steps, which is particularly important when maintaining H24 on-call coverage. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The learning curve to fully master the platform is steeper than with some competing EDR/XDR solutions, especially when it comes to fine-tuning detection rules to cut down on noise without sacrificing coverage. New analysts on the team need meaningful ramp-up time before they’re fully productive. Licensing and add-on module costs can also add up quickly if you want full XDR capability (network, cloud, identity) rather than endpoint-only coverage. Occasionally, the alert-correlation logic feels opaque, which makes it harder to explain in post-incident reporting why certain events were grouped together. Review collected by and hosted on G2.com.