No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon vs Palo Alto Networks AutoFocus comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
Palo Alto Networks AutoFocus
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
Threat Intelligence Platforms (TIP) (20th)
 

Mindshare comparison

Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Palo Alto Networks AutoFocus1.4%
Recorded Future6.1%
Anomali3.9%
Other88.6%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.
Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The one feature of Palo Alto Networks Traps that our organization finds most valuable is the App ID service."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"Since using Cortex XDR by Palo Alto Networks, our MTTR has reduced, which means the mean time to resolve any ticket has been reduced."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"WildFire AI is the best option for this product."
"There has been a significant reduction of approximately 70% to 80% in our internal MTTR and MTTD metrics, now around five to eight minutes whereas previously it was hours, which has helped tremendously."
"I like the centralized console and the predictive analysis it does of malware. It is very stable and also scalable."
"It's given me a level of confidence that my network is secure."
"CrowdStrike Falcon has positively impacted my organization by allowing fewer people to do more workloads, so it has saved us time, money, and effort."
"The product's deployment phase is easy."
"Its integration capability is valuable. It integrates easily with any OS."
"We can protect against the worst level of attacks."
"All the features are beneficial."
"Using CrowdStrike Falcon has changed the way my security team detects, investigates, and responds to threats by giving my team a single source outside of our SIEM to be able to quickly and easily drill into the incident and understand what the alert from our SIEM actually means."
"CrowdStrike enables the infrastructure managers to visualize all the events and get information about the network."
"The logs play a crucial role as they contribute to blocking unwanted Internet traffic."
"It's a very good solution, it identifies critical attacks and alerts you."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"It is very easy to install and set up AutoFocus."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"The most valuable feature is alerting."
"The feature that I like best is the dashboard."
 

Cons

"If you compare it to SentinelOne, which has more functionalities and detection capabilities on an open platform, the pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks."
"The main issue I could point out is the offline agents and the way that it is missing."
"It'll help if customization was easier."
"The price could be a little lower."
"If Palo Alto reduces the pricing slightly for their products, it would make them more scalable in markets such as India and globally for cybersecurity."
"They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
"It is a complex solution to implement."
"Product might have some bugs."
"The pricing structure should allow for some flexibility."
"So far, the benefits I have seen from having multiple security capabilities on a single platform have been limited, but based on the testing, we see that it is identifying threats and it has shown us proactive capabilities to shut down the threats."
"They don't really have anything when it comes to scanning attachments."
"The technical support could improve because I am in India and the support I receive is from the UK or Australia. It is difficult to manage the time difference. The service could be faster. However, when we do have the support they are knowledgeable."
"They should provide us with good visibility for everything."
"The solution should have included remote wipe capability out of the box."
"It can be expensive depending on the features you select."
"CrowdStrike Falcon can improve their supportability of legacy devices."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"It would be helpful to have better documentation for configuring and installing the solution."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"Palo Alto Networks AutoFocus is not affordable."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
 

Pricing and Cost Advice

"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"Cortex XDR’s pricing is very reasonable."
"The price of the product is not very economical."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"Our customers have expressed that the price is high."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"The pricing is not bad. It's on the higher end of the market, but you get what you pay for."
"Different components are additional price points. We got the components that were right for us, but other organizations may require more (or less) components to suit their needs."
"CrowdStrike is well priced. On a yearly basis, it costs between $60 and $100 per user."
"The other administrator and I can log in to check the exact details of what happened, what was running, and what caused the detection. We know exactly what was happening on the end users PC and we can tell if it's something that we actually need or something that's malicious."
"The cost of CrowdStrike Falcon in Latin America seems high relative to the economic conditions in the region."
"CrowdStrike Falcon is one of the more expensive endpoint solutions on the market."
"Crowdstrike Falcon is relatively cheap."
"The tool is a little bit expensive compared to other products, but I think it's okay owing to its quality."
"The solution is reasonably priced."
"It is expensive."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
914,262 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
10%
Outsourcing Company
9%
Manufacturing Company
9%
Computer Software Company
8%
Performing Arts
14%
Outsourcing Company
11%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Is Crowdstrike Falcon better than Trend Micro Deep Security?
I like that Crowdstrike allows me to easily correlate data between my firewalls. What’s most useful for my needs is t...
What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confi...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Telkom Indonesia
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
914,262 professionals have used our research since 2012.