---
title: Palo Alto Networks Cortex XSOAR Reviews
meta_title: 'Palo Alto Networks Cortex XSOAR Reviews 2026: Details, Pricing, & Features
  | G2'
meta_description: Filter 28 reviews by the users' company size, role or industry to
  find out how Palo Alto Networks Cortex XSOAR works for a business like yours.
aggregate_rating:
  rating_value: 4.6
  review_count: 28
  scale: '5'
date_modified: '2026-08-09'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---


# Palo Alto Networks Cortex XSOAR Reviews
**Vendor:** Palo Alto Networks  
**Category:** [Security Orchestration, Automation, and Response (SOAR) Software](https://www.g2.com/categories/security-orchestration-automation-and-response-soar)  
**Average Rating:** 4.6/5.0  
**Total Reviews:** 28
## About Palo Alto Networks Cortex XSOAR
Palo Alto Networks&#39; Cortex XSOAR is a comprehensive Security Orchestration, Automation, and Response (SOAR) platform designed to streamline and enhance security operations. By integrating automation, case management, real-time collaboration, and threat intelligence management, Cortex XSOAR empowers security teams to respond to incidents more efficiently and effectively. Key Features and Functionality: - Process Standardization and Automation: Cortex XSOAR offers over 270 out-of-the-box playbooks, enabling the automation of numerous security use cases. These playbooks orchestrate response actions across more than 350 third-party products, facilitating seamless integration and operational consistency. - Security-Focused Case Management: The platform unifies alerts, incidents, and indicators from various sources into a single case management framework. This consolidation accelerates incident response by providing a comprehensive view of security events. - Real-Time Collaboration: Cortex XSOAR includes a Virtual War Room equipped with built-in ChatOps and a command-line interface. This feature allows security teams to collaborate in real time, execute commands across the entire product stack, and manage incidents more effectively. - Threat Intelligence Management: The platform aggregates disparate threat intelligence sources, customizes and scores feeds, and matches indicators against the organization&#39;s specific environment. This capability enables security teams to take informed actions swiftly. Primary Value and Problem Solving: Cortex XSOAR addresses the challenges faced by security teams, such as the overwhelming volume of alerts and the need for rapid incident response. By automating repetitive tasks and standardizing processes, the platform reduces the time spent on incidents by up to 90%, allowing analysts to focus on critical threats. The integration of threat intelligence management with SOAR capabilities ensures that organizations can operationalize threat feeds effectively, enhancing their overall security posture. Additionally, the platform&#39;s extensive integration ecosystem, with over 360 third-party integrations, enables organizations to orchestrate complex workflows across their existing security infrastructure without extensive custom development.



## Palo Alto Networks Cortex XSOAR Pros & Cons
**What users like:**

- Users value the **powerful automation** capabilities of Cortex XSOAR, enhancing incident response efficiency and customization. (3 reviews)
- Users enjoy the **great UI** of Palo Alto Networks Cortex XSOAR, which enhances usability and customization significantly. (2 reviews)
- Users admire the **accuracy of information** in Palo Alto Networks Cortex XSOAR, enhancing safety and efficiency in operations. (1 reviews)
- Users value the **powerful automation** capabilities of Cortex XSOAR for efficient incident response management. (1 reviews)
- Users appreciate the **direct customer support** of Palo Alto Networks Cortex XSOAR, enhancing their overall experience. (1 reviews)
- Data Management (1 reviews)
- Ease of Use (1 reviews)
- Easy Integrations (1 reviews)
- Users value the **integration capabilities** of Cortex XSOAR, enabling effective incident management across large environments. (1 reviews)
- Integrations (1 reviews)

**What users dislike:**

- Users find the **learning curve steep** , requiring significant time and effort to effectively manage Cortex XSOAR&#39;s complexities. (2 reviews)
- Users feel that the **limited customization** options hinder the overall reporting experience in Cortex XSOAR. (1 reviews)
- Users find **logging issues** arise from hard-to-read data logs that require opening in a new tab for clarity. (1 reviews)
- Users find **log management issues** frustrating, as reading data logs quickly is challenging due to window size limitations. (1 reviews)
- Users find the **reporting lacking** and desire enhanced customization options for a better experience. (1 reviews)
- Users find the **time consumption** of Palo Alto Networks Cortex XSOAR frustrating as it requires significant effort to manage effectively. (1 reviews)


## Palo Alto Networks Cortex XSOAR Discussions
  - [What is Palo Alto Networks Cortex XSOAR used for?](https://www.g2.com/discussions/what-is-palo-alto-networks-cortex-xsoar-used-for)
  - [add more use](https://www.g2.com/discussions/add-more-use) - 1 upvote

- [View Palo Alto Networks Cortex XSOAR pricing details and edition comparison](https://www.g2.com/products/palo-alto-networks-cortex-xsoar/reviews?page=2&section=pricing&secure%5Bexpires_at%5D=2026-08-12+11%3A40%3A46+-0500&secure%5Bsession_id%5D=5dc15f9f-9629-46fc-ae49-773683c39bda&secure%5Btoken%5D=cb142368620f08af51fb225fbaefe689e5c4316c48b97ed80a717180d258194a&format=llm_user)
## Palo Alto Networks Cortex XSOAR Integrations
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews)

## Palo Alto Networks Cortex XSOAR Features
**Orchestration**
- Asset Management
- Security Workflow Automation
- Deployment
- Sandboxing
- Remediation Management

**Automation**
- Workflow Mapping
- Workflow Automation
- Automated Remediation
- Log Monitoring

**Information**
- Proactive Alerts
- Malware Detection
- Intelligence Reports
- Threat Intelligence
- Real-time Alerts

**Orchestration**
- Security Orchestration
- Data Collection
- Threat Intelligence
- Data Visualization

**Personalization**
- Endpoint Intelligence
- Security Validation
- Dynamic/Code Analysis
- Event Analysis
- Web-Application Security
- Application Security

**Response**
- Alerting
- Performance Baselin
- High Availability/Disaster Recovery

**Additional Functionality**
- Generative AI
- Collaboration Tools
- Incident Management
- AI Copilot
- Reporting/Analytics
- Threat Response
- Key Performance Indicators
- Risk Alerts
- Performance Metrics
- Third-Party Integrations

**Generative AI**
- AI Text Summarization
- Generate Attack Scenarios
- Generate Threat Detection Rules
- Generate Threat Summaries
- Generative AI

**Agentic AI - Threat Intelligence**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Additional Functionality**
- Real-Time Reporting
- Real-Time Analytics
- Network Monitoring
- API
- Reporting/Analytics
- Alerts/Notifications
- Behavior Analytics
- AI Copilot
- Activity Dashboard
- Profiling
- Cloud Backup
- Data Visualization
- Activity Monitoring
- Network Scanning
- Event Logs
- Monitoring
- Server Monitoring
- Vulnerability Scanning
- Incident Reporting
- Activity Tracking
- Reporting & Statistics
- Network Provisioning
- Prioritization
- Threat Response
- Real-Time Data
- IT Reporting

## Top Palo Alto Networks Cortex XSOAR Alternatives
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews) - 4.4/5.0 (274 reviews)
  - [Tines](https://www.g2.com/products/tines/reviews) - 4.7/5.0 (400 reviews)
  - [Splunk SOAR (Security Orchestration, Automation and Response)](https://www.g2.com/products/splunk-soar-security-orchestration-automation-and-response/reviews) - 4.4/5.0 (40 reviews)

