No more typing reviews! Try our Samantha, our new voice AI agent.

Cybereason XDR vs Trellix Endpoint Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
115
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Cybereason XDR
Ranking in Extended Detection and Response (XDR)
24th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
3
Ranking in other categories
No ranking in other categories
Trellix Endpoint Security P...
Ranking in Extended Detection and Response (XDR)
8th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
167
Ranking in other categories
Endpoint Protection Platform (EPP) (7th), Endpoint Detection and Response (EDR) (8th)
 

Mindshare comparison

As of August 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.5%, down from 5.0% compared to the previous year. The mindshare of Cybereason XDR is 1.0%, up from 0.7% compared to the previous year. The mindshare of Trellix Endpoint Security Platform is 3.4%, down from 3.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.5%
Trellix Endpoint Security Platform3.4%
Cybereason XDR1.0%
Other91.1%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Peter Nowak - PeerSpot reviewer
Business Development Manager for Cybereason at Bechtle
Integration of multiple firewalls enables advanced threat detection
The integration of data from firewalls and Active Directory is most valuable. Cybereason XDR facilitates two-way communication, where the firewall sends data to the Cybereason system, and it can communicate with the firewall to stop unwanted communication. Customers can deal with multiple types of firewalls with ease. The behavioral analytics help detect advanced threats when attackers use existing software. The multilayered protection approach, including NGAV, integrates XDR detection with antivirus to assess and counter threats effectively.
AmitKumar22 - PeerSpot reviewer
Product Manager at Frontier Business systems
Strong endpoint protection has simplified compliance and reduced effort for large user environments
One of the best features of Trellix Endpoint Security Platform is its endpoint security, and I have been using it for the last four and a half to five years, so I can say this is one of the best EDR endpoint security solutions I have ever seen. The features that make Trellix Endpoint Security Platform stand out for me are ease of use and analytics, which I really appreciate the most. Trellix Endpoint Security Platform positively impacts my organization, ensuring we are compliant with SOC 2, HIPAA, and all other compliance requirements, so there are no issues with that.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"I recognize that Cortex XDR by Palo Alto Networks is one of the best products in its category regarding capabilities."
"I've found the solution to be highly scalable for enterprises."
"Palo Alto Networks Traps improves our security posture and lowers risk by providing next-gen methods to combat against modern threats on all the major platforms."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"The solution allows control over the user and his machine through Cortex XDR security policies."
"The dashboard is customizable."
"Cortex XDR by Palo Alto Networks is specifically designed to prevent zero-day attacks and is part of an ecosystem of Palo Alto, providing customers with a long-term vision to modify and redesign how security is applied in their company."
"The solution has an investigation feature, which is useful for building storylines."
"Cybereason XDR's most useful feature is the investigation."
"The integration of data from firewalls and Active Directory is most valuable."
"The features we have found most valuable have been containment as well as the ability to triage agent activities."
"The product has a robust reporting feature"
"If the network has seen something, we can use that to put a block to all the endpoints."
"The platform’s most valuable features are ease of use, integration, and deployment."
"The solution is stable."
"Trellix Endpoint Security Platform has positively impacted our organization with strong protection against malware and ransomware, greatly improving our ability to detect and block threats in real time, and features like ATP and Exploit Prevention help reduce malware and zero-day attacks."
"It is a stable solution...The solution's technical support is good."
"McAfee MVISION Endpoint is stable."
 

Cons

"It is not a suitable solution if you are looking for a single product with multiple features such as DLP, encryption, rollback, etc."
"The connection to the internet has not performed as expected."
"This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance."
"Cortex XDR should have a lightweight agent, and the agent size should not be heavy."
"It would be better if they could educate the customers more. Some sort of seminars and roadshows will help educate the customers and show what the product can do. The price could be better. It would also help if they had a team for deployment and support."
"This is a very costly product."
"It is a complex solution to implement."
"It'll help if customization was easier."
"There could be more integrations with other data sources like NDR systems."
"The one thing we sometimes have issues with is its integration with other security applications like antiviruses."
"Cybereason's customer support could be better."
"Customer service is rated as a five out of ten. When they work and reach the right level, they are helpful, but getting to the right person can be time-consuming."
"Performance is a problematic area in the solution needing improvement."
"There should be better integration between the ePolicy Orchestrator and FireEye console. The integration of both consoles should be better."
"The integration and display of the dashboards have to be done better."
"Their support is not good and needs to be improved."
"Upgrading to new versions isn't easy and it can take a long time. Also, other solutions' tamper protection features are better than FireEye's. Clients should have access to our local information, but they shouldn't change settings on the system itself."
"Tech support is not as helpful as they were in the past."
"Initially, we ran into issues running full-disk encryption and certain versions of disk defragmentation software."
"The solution is not really stable. Every time we open a ticket with McAfee, their response differs and they are not consistent."
 

Pricing and Cost Advice

"We didn't have to pay any additional fee for the cloud instance. It just came with the renewal, which was nice."
"The cost depends on your chosen license type, like Pro or other licenses."
"Compared to CrowdStrike, Cortex XDR is an expensive solution."
"I don't recall what the cost was, but it wasn't really that expensive."
"I am using the Community edition."
"The pricing is a little high. It is per user per year."
"The pricing is a little bit on the expensive side."
"Our customers have expressed that the price is high."
"The solution is cheaper than Microsoft Defender. It has a subscription and no standard license."
"Pricing is fair."
"Its price is very high. It is higher than its competitors, and it should be less."
"The pricing is great and licensing fees are billed on a yearly basis."
"McAfee's prices are flexible and can be quite competitive, although there are other solutions that are even more so."
"No comment."
"We pay for the license on an annual basis."
"It is based on an annual subscription."
"The pricing is mid-ranged and quite reasonable compared to other similar products."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
908,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
10%
Manufacturing Company
11%
Computer Software Company
11%
Outsourcing Company
9%
Comms Service Provider
8%
Manufacturing Company
10%
Financial Services Firm
9%
Construction Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise21
Large Enterprise54
No data available
By reviewers
Company SizeCount
Small Business68
Midsize Enterprise39
Large Enterprise67
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Cybereason XDR?
There could be more integrations with other data sources like NDR systems. Additionally, technical support has been s...
What is your primary use case for Cybereason XDR?
I use Cybereason XDR for customers who don't have a SOC or managed SOC yet and want to be protected on more than thei...
What advice do you have for others considering Cybereason XDR?
I rate Cybereason XDR a nine out of ten. I recommend having hands-on experience and doing some threat hunting to fami...
How does McAfee Endpoint Security compare with MVISION?
The flexible manageability of McAfee Endpoint Security is one of our favorite aspects of this solution. You can deplo...
How does Crowdstrike Falcon compare with FireEye Endpoint Security?
The Crowdstrike Falcon program has a simple to use user interface, making it both an easy to use as well as an effec...
What is your experience regarding pricing and costs for McAfee Endpoint Security?
I don't have visibility on pricing because it is negotiated by a different team, as I look after the technical side.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
McAfee Endpoint Security, McAfee Endpoint Protection, Intel Security Total Protection for Endpoint, McAfee Complete Endpoint Protection, Trellix Endpoint Security (ENS)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
MOTOROLA MOBILITY
inHouseIT, Seagate Technology
Find out what your peers are saying about Cybereason XDR vs. Trellix Endpoint Security Platform and other solutions. Updated: June 2026.
908,858 professionals have used our research since 2012.