Joe F.
JF
Joe F.
UNICEF National Internship Program
Enterprise (> 1000 emp.)
"Fast, Seamless Region Connections with No Noticeable Latency"
4/5
What do you like best about Cortex XDR?

So far I don't recognize any latency issues even while it was running in the background. Also it can be connected to different regions quite fast and seamless. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

Sometimes it can occupy some memory when my computer is running on a lot of ai processes that are resource hungry. Sometimes region switching fail too Review collected by and hosted on G2.com.

Verified User in Oil & Energy
UO
Verified User in Oil & Energy
Mid-Market (51-1000 emp.)
"Impressive AI Threat Detection with Clear, End-to-End Attack Stories"
4/5
What do you like best about Cortex XDR?

Honestly, it's the way it just gets the big picture. Instead of drowning you in a million random alerts, it stitches everything together from endpoints, network, cloud, and identity stuff into these clear attack stories. The AI and behavioral analytics are seriously impressive - it catches sneaky threats that other tools miss, and the root cause analysis saves me so much time during investigations. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

he biggest thing that still bugs me is the learning curve and how complex it can feel at first. The interface is packed with features, which is great once you know it, but it can overwhelm you in the beginning and takes real time to tune properly. Pricing is another sore spot - it's definitely on the expensive side, especially with the extra costs for data lake storage and the licensing complexity. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"XDR’s Smart Alert Grouping and Automation Cut SOC Triage Time"
4/5
What do you like best about Cortex XDR?

The grouping engine is the standout feature. XDR automatically correlates related alerts into unified incidents, so instead of triaging 30 individual alerts you're reviewing 3-4 cases with full context already stitched together — endpoint telemetry, network activity, and identity signals all in one view.

The causality chain visualization makes it straightforward to trace process trees and understand attack flow without manually pivoting between tools. You can see parent-child process relationships, file writes, network connections, and registry changes in a single timeline.

Automation profiles let you define response actions (isolate host, kill process, quarantine file) that trigger automatically on high-confidence detections, which means analysts only handle the cases that genuinely need human judgment. This significantly reduces alert fatigue and manual toil for the SOC — routine malware detections get contained without anyone touching them.

The interface is clean and the query language (XQL) gives you direct access to raw telemetry when you need to dig deeper than the pre-built views offer. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

No out of box fleet sweeping feature. Threat intel integration is weak and lacks actionable context. The agentic assistant (Cortex AI) still has rough edges and provides limited practical value during real investigations. Review collected by and hosted on G2.com.

Verified User
G
Verified User
Small-Business (50 or fewer emp.)
"Comprehensive Security, Some Complexity"
4/5
What do you like best about Cortex XDR?

I use Cortex XDR to block malware, detect hidden attacks, and investigate security threats. The best part about it is how it automatically links data points from different IT sources into a single timeline, which eliminates the need for analysts to manually gather pieces from firewalls, emails, endpoints, or cloud logs. I also find the root cause analysis, native integration, smart response, incident grouping, and cross-data analytics to work especially well. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

I find the policy management capability very complex, even though it's a market-leading security platform. There's rigid alert suppression, feature gaps across OS, high resource consumption, and a steep learning curve. Additionally, while cloud provisioning was easy, I found the agent rollout quite complex. Review collected by and hosted on G2.com.

YH
yikhong h.
Senior Network Security Engineer
Small-Business (50 or fewer emp.)
"Smart Score and Identity Threat Detection Make Prioritizing Threats Easy"
4.5/5
What do you like best about Cortex XDR?

Smart Score and it can automate incident scoring that helps analysts prioritize the most critical threats first.

Identity Threat Detection and it can correlate user behavior with endpoint activity to spot compromised credentials. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

Cortex XDR by Palo Alto Networks is primarily integrated within the Palo Alto ecosystem. As a result, there are significant functionality gaps between the Windows, Linux, and Mac versions. Additionally, the cost of Cortex XDR is comparatively high. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"Automatic correlation and causal chain of Cortex XDR facilitate root cause analysis"
4/5
What do you like best about Cortex XDR?

The main advantage of Cortex XDR lies in its ability to automatically aggregate and correlate data from multiple vectors (such as endpoints, network, and identities). The Data Stitching functionality and the presentation of the causal chain significantly simplify root cause analysis, allowing precise identification of the entry vector and the behavior of complex routines, such as Living off the Land attacks. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

The main drawbacks do not lie in the detection capability, but rather in the technical complexity of XQL, the financial investment, and the effort required in the initial phase of agent optimization to avoid performance impact or false positives. Review collected by and hosted on G2.com.

Verified User in Banking
CB
Verified User in Banking
Mid-Market (51-1000 emp.)
"Powerful Threat Visibility, but a Steep Learning Curve and Tuning Needed"
3/5
What do you like best about Cortex XDR?

What I like best about Cortex XDR is how it brings data from endpoints, network activity, and other security sources into one place. It makes investigating threats much faster because you can see the full picture instead of jumping between different tools. The automation and AI-driven analytics also help reduce alert fatigue, so I can focus on the incidents that actually matter Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

What I dislike about Cortex XDR is that it can have a steep learning curve, especially when you're first getting used to the interface and investigation workflows. Some advanced features take time to master, and the amount of data can feel overwhelming. It can also generate noisy alerts if it's not properly tuned, so regular policy and detection adjustments are important Review collected by and hosted on G2.com.

Tej D.
TD
Tej D.
Secretary
Telecommunications
Enterprise (> 1000 emp.)
"Excellent Threat Detection and Seamless Integration with Palo Alto Networks Tools"
5/5
What do you like best about Cortex XDR?

Excellent detection score for the latest attack. Can be easily integrated into the latest tools like Palo Alto Networks Next-Generation Firewalls (NGFW) and Prisma. can be accomulate and stitch the multi-source data. Flowlss tools to work. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

Needs to take complex knowledge to operate. Takes a bit more resources than needed due to its legacy system. Initial implementation needs complex fine-tuning of rules and configuration. Complex Learning curve Review collected by and hosted on G2.com.

Verified User in Manufacturing
AM
Verified User in Manufacturing
Enterprise (> 1000 emp.)
"Lightweight agent and a Modern Console with Strong Vendor Support"
5/5
What do you like best about Cortex XDR?

Real time detection and prevention, lightweight agent as well as agentless solution available, managed through a single modern cloud-based console. Easy integration with data sources such as Amazon S3, Microsoft Teams, Email messaging, Google Cloud, and more. The Cortex XDR console offers fast and clean user interface, and it opens fast and performs very well. Cost may be high depending on the features selected and the number of devices, but in our deployment it was good investment, considering the level of protection we received and the quality of the support from the vendor. The built-in AI intelligence is an added value. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

Licensing can be confusing, especially with the cloud protection, and may add cost quickly. New releases and the added new features require constant learning. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Verified User in Computer & Network Security
Mid-Market (51-1000 emp.)
"Cortex XDR Delivers Powerful Endpoint Control and Extended Detection"
4/5
What do you like best about Cortex XDR?

The cortex XDR is not a typical EDR solution it has extended detection and response capabilities which gives full control on the endpoints integrated with it. From isolation to shell control all can be done through cortex XDR. Review collected by and hosted on G2.com.

What do you dislike about Cortex XDR?

1- The GUI of the cortex XDR solution is not user friendly.

2- The solution is very expensive for small and mid-size organizations.

3- The deployment of the solution is more complex than normal XDR solution. Review collected by and hosted on G2.com.